Weblogic Server 12.1.2 - Java Deserialisation Vulnerability
Hi. I have a customer who has just encountered this issue below;
"We got a security alert while running the nesus scan which says : Nessus was able to exploit a Java deserialization vulnerability by sending a crafted Java object. " and it's linked to CVE-2017-10271. Kindly provide the patch details to get this vulnerability fixed." (WLS_VERSION: 12.1.2.0.0. JDK_VERSION: 1.7.0_181)
Customer raised an SR and was advised an 'exception request' was required for this version of WLS before a bug can be raised. Is there a link or a template for creating such an exception ??
Note from Support:
"Customer has support till 2019 But as per the error correction policy support ended for WebLogic 12.1.2.0 in JUN 2016. To release patches or PSU’s they need “Exception”.........