WebLogic Deserialization of Untrusted Data Vulnerability - CVE-2019-17571 - Vulnerability Database

WebLogic Deserialization of Untrusted Data Vulnerability - CVE-2019-17571

Critical
Reference: CVE-2019-17571
Title: WebLogic Deserialization of Untrusted Data Vulnerability
Overview:

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.