Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Zero-Day exploit at Java lib Common Collections

$
0
0

Hi Gurus,

 

I found the a post stating there is a Zero-Day exploit in the common collections function InvokerTransformer. Found by Gabriel Lawrence and Chris Frohoff shown in their presentation.
http://de.slideshare.net/frohoff1/appseccali-2015-marshalling-pickles

 

Until now I have found no SAP Security Notes relating to this and stating a possible solution or how if there are any tools affected.

 

Did anyone find any document related to this?

 

Edit: There was already an other post to this topic -> SAP AS Java affected from commons-collection vulnerability?

 

Kind regards,

Niklas


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>