CVE 2017-10271: wls-wsat Component Deserialization vulnerability
I've been asked to look at a number of Oracle Forms 11g middle tiers that run on Weblogic 10.3.6. These aren't public facing systems, but it does appear that they have the above WLS-WSAT vulnerability.
There are a number of wls-wsat.war files located in the Weblogic folders and also in the forms and reports middle tiers as well. We moved these wls-wsat.war files out of their original locations, renamed them, and then rebooted the server. However a vulnerability test subsequently undertaken showed the vulnerability still persisted.
We do plan on patching these servers soon but before we can get suitable downtime, is there any way of manually disabling or de-installing the wls-wsat component internally to remove the vulnerability?