Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

Oracle WebLogic Server 10.3.2 vulnerability repair method

2025-01-18 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Database >

Share

Shulou(Shulou.com)06/01 Report--

The modification method is:

1. Decompress modules/com.bea.core.apache.commons.collections_3.2.0.jar under weblogic

two。 Delete the InvokerTransformer.class class in it

3. Repackage com.bea.core.apache.commons.collections_3.2.0.jar

4. Delete the cache under the domain and restart

Test strategy:

The security problems of weblogic deserialization are repaired in the daily test environment, and the deployed system applications are tested after repair.

The first round of targeted testing, specifically for the core commonly used functional modules for functional testing.

The second round is continuous testing, and the week-long task tests are tested in this environment as usual to see if they will be affected. And it will be tested as a test environment all the time.

Test results:

Part of the program bug has been found during the test, but the defects caused by deserialization problems have not been found.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Database

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report