A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
foxglovesecurity.com
A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
1–10 of 27 posts
Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#2Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#3Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#4Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#5Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#6Black hats are going to have fun with this one. :-(
Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#7The first thing I thought was "written in Java". The more straightforward headline would have been better, I think.
Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#8Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#9The first thing I thought was "written in Java". The more straightforward headline would have been better, I think.
Re: A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
#10The first thing I thought was "written in Java". The more straightforward headline would have been better, I think.
The straightforward headline would be "Security flaw in commons-collection deserialization". The anti-java snark really isn't welcome.
Something that is called out in the Java secure coding guidelines:
http://www.oracle.com/technetwork/java/seccodeguide-139067.h...
and is something that goes way back in many languages. It seems to be a vuln pattern that keeps getting repeated sadly.