Collected research
Java Deserialization w/ Apache Commons Collections in WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS
What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.
Apache Commons Collections contains a gadget chain whose readObject ends in an arbitrary command execution, so any Java service that deserializes attacker-supplied data is pre-authentication remote code execution. The post shows how to recognise serialized objects on the wire and gives working exploits for WebSphere, JBoss, Jenkins, WebLogic and OpenNMS.
Record
- Document
- What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.
- Researcher
- Stephen Breen
- Published by
- foxglovesecurity.com
- Date
- Topic
- Server
In the archive
Related sources
- Marshalling Pickles Slides
- Java deserialization explained by Matthias Kaiser
- ysoserial
- JavaUnserializeExploits
Tags
This page is the archive's own catalogue record. The research is the work of Stephen Breen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .