Seek help to get solution for the VA finding
Hi team,
I'm seeking advice & solution for the following findings :
Orace Weblogic server : 12.2.1.2.0
1. Oracle WebLogic Server Deserialization RCE (CVE-2018-2628)
The remote Oracle WebLogic server is affected by a remote code execution vulnerability in the Core Components subcomponent due to unsafe deserialization of Java objects by the RMI registry. An unauthenticated, remote attacker can exploit this, via a crafted Java object, to execute arbitrary Java code in the context of the WebLogic server.
2. Oracle WebLogic Server Deserialization RCE (CVE-2018-2893)
The remote Oracle WebLogic server is affected by a remote code execution vulnerability in the Core Components subcomponent due to unsafe deserialization of Java objects. An unauthenticated, remote attacker can exploit this, via a crafted Java object, to execute arbitrary Java code in the context of the WebLogic server.