Black & White Path
Aug 24, 2026 · Information Security
No‑Credentials RCE: One POST request grants root on Pakistan’s largest bank
A security analysis reveals that an unauthenticated Java deserialization flaw (CVE‑2017‑10271) in Oracle WebLogic's WS‑AT endpoint lets an attacker obtain a root shell on HBL’s internet‑facing banking nodes with a single POST request, then harvest credentials, hijack sessions, persist, and move laterally, while additional related bugs amplify the risk.
BankingCVE-2017-10271Java Deserialization
0 likes · 10 min read
