Tagged articles

Java Deserialization

1 articles · Page 1 of 1
Black & White Path
Black & White Path
Aug 24, 2026 · Information Security

No‑Credentials RCE: One POST request grants root on Pakistan’s largest bank

A security analysis reveals that an unauthenticated Java deserialization flaw (CVE‑2017‑10271) in Oracle WebLogic's WS‑AT endpoint lets an attacker obtain a root shell on HBL’s internet‑facing banking nodes with a single POST request, then harvest credentials, hijack sessions, persist, and move laterally, while additional related bugs amplify the risk.

BankingCVE-2017-10271Java Deserialization
0 likes · 10 min read
No‑Credentials RCE: One POST request grants root on Pakistan’s largest bank