Exploitation Summary
EIP tracks 2 public exploits for CVE-2019-4279.
PoCs published by b0yd, including Metasploit module exploits/windows/ibm/ibm_was_dmgr_java_deserialization_rce.
AI-analyzed exploit summary This Metasploit module exploits a deserialization vulnerability in IBM WebSphere Application Server Network Deployment (CVE-2019-4279) to achieve remote code execution. It constructs malicious serialized objects to execute arbitrary commands or upload payloads.
Description
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
Exploits (2)
This Metasploit module exploits a deserialization vulnerability in IBM WebSphere Application Server Network Deployment (CVE-2019-4279) to achieve remote code execution. It constructs malicious serialized objects to execute arbitrary commands or upload payloads.
This Metasploit module exploits a Java deserialization vulnerability in IBM WebSphere Application Server Network Deployment (CVE-2019-4279) to achieve remote code execution. It constructs malicious serialized objects to add a neighbor node and broadcast a task, ultimately executing arbitrary commands or payloads on the target system.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H