PT-2023-27516 · Unknown · Weblogic-Framework

Published

2023-08-25

·

Updated

2023-09-01

·

CVE-2023-40571

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions weblogic-framework versions 0.2.3 and prior
Description The issue is related to a deserialization vulnerability that may lead to remote code execution. When the weblogic-framework receives the command echo, it directly deserializes the data returned by the server without verifying it. The classloader loads a lot of deserialization calls, and malicious serialized data returned by the server can cause remote code execution.
Recommendations For versions 0.2.3 and prior, update to version 0.2.4 to resolve the issue. As a temporary workaround, consider disabling the deserialization of data returned by the server until a patch is available. Restrict access to the echo command to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2023-40571
GHSA-HJWJ-4F3Q-44H3

Affected Products

Weblogic-Framework