Using the My Oracle Support Portal (MOSC)

MOSC Banner

Weblogic Server 12.1.2 - Java Deserialisation Vulnerability

Hi. I have a customer who has just encountered this issue below;

"We got a security alert while running the nesus scan which says : Nessus was able to exploit a Java deserialization vulnerability by sending a crafted Java object. " and it's linked to CVE-2017-10271. Kindly provide the patch details to get this vulnerability fixed."  (WLS_VERSION: 12.1.2.0.0. JDK_VERSION: 1.7.0_181)

Customer raised an SR and was advised an 'exception request' was required for this version of WLS before a bug can be raised. Is there a link or a template for creating such an exception ??

Note from Support:

"Customer has support till 2019 But as per the error correction policy support ended for WebLogic 12.1.2.0 in JUN 2016. To release patches or PSU’s they need “Exception”.........

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center