Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Oracle WebLogic Node Manager allows arbitrary configuration via UNC path

Summary

Bishop Fox advisory: WebLogic Node Manager 10.3.3 and earlier let unauthenticated attackers redirect its config and password files to an attacker-controlled UNC path, then run commands; fixed in 2011.
Published
Collected

original ↗

Related coverage

back