Oracle Weblogic Server (MOSC)

MOSC Banner

CVE 2017-10271: wls-wsat Component Deserialization vulnerability

edited Dec 16, 2018 4:10AM in Oracle Weblogic Server (MOSC) 7 commentsAnswered

I've been asked to look at a number of Oracle Forms 11g middle tiers that run on Weblogic 10.3.6. These aren't public facing systems, but it does appear that they have the above WLS-WSAT vulnerability.

There are a number of wls-wsat.war files located in the Weblogic folders and also in the forms and reports middle tiers as well. We moved these wls-wsat.war files out of their original locations, renamed them, and then rebooted the server. However a vulnerability test subsequently undertaken showed the vulnerability still persisted.

We do plan on patching these servers soon but before we can get suitable downtime, is there any way of manually disabling or de-installing the wls-wsat component internally to remove the vulnerability?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center