Blog
A WebLogic Vulnerability Highlights the Path-Based Authorization Dilemma
By Craig Young on Mon, 11/02/2020
A WebLogic server vulnerability fixed by the October CPU has come under active exploitation after a Vietnamese language blog post detailed the steps needed to bypass authentication and achieve remote code execution on unpatched systems. Although there have been a series of actively exploited WebLogic deserialization bugs, the exploit payload in this...