Web Hack List

Collected research

Exploiting JNDI Injections in Java

Java 8u191 stopped JNDI lookups loading remote classes, but a malicious RMI or LDAP server can still return a reference naming Tomcat's BeanFactory as its object factory. BeanFactory builds any bean and its forceString property redirects a setter to an arbitrary one-String method, so targeting javax.el.ELProcessor.eval evaluates attacker expression language and runs commands.

Record

Published by
Veracode
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Veracode, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .