Collected research
Exploiting JNDI Injections in Java
Java 8u191 stopped JNDI lookups loading remote classes, but a malicious RMI or LDAP server can still return a reference naming Tomcat's BeanFactory as its object factory. BeanFactory builds any bean and its forceString property redirects a setter to an arbitrary one-String method, so targeting javax.el.ELProcessor.eval evaluates attacker expression language and runs commands.
Record
- Published by
- Veracode
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Veracode, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .