Web Hack List

Collected research

Miracle - One Vulnerability To Rule Them All

Oracle ADF Faces exposes a resource servlet that deserialises attacker-controlled data taken straight from the URL path, giving unauthenticated remote code execution across every Oracle Fusion Middleware product built on ADF. It is chained with a pre-auth SAML XPath SSRF in Access Manager and a new coherence.jar gadget chain that defeats WebLogic's class-loader blacklist.

Record

Researcher
Peterjson and @peterjson
Published by
Medium
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Peterjson and @peterjson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .