Java Deserialization Vulnerability

Quang D Le qle3 at lsu.edu
Fri Nov 20 16:59:56 EST 2015


All,

Anybody know if Shibboleth IDP server is vulnerable to the Java 
Deserialization bug?

http://www.darkreading.com/informationweek-home/why-the-java-deserialization-bug-is-a-big-deal/d/d-id/1323237

http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/

I followed the FoxGlove Security article, and found that Shibboleth IDP 
server does have the vulnerable, commons-collections-3.2.1.jar, in 
/opt/shibboleth-idp/lib/commons-collections-3.2.1.jar:

grep -R InvokerTransformer .
Binary file ./lib/commons-collections-3.2.1.jar matches

Does anybody know if commons-collections-3.2.1.jar can be removed? If 
so, what are the consequences? (I'm guessing a lot)

Any information is greatly appreciated. Thank you.

-- 
Quang D Le
ITS - Security
225-578-4932
qle3 at lsu.edu


More information about the users mailing list