johndekroon / serializekiller

Mass scanner for the Java serialize bug
The Unlicense
148 stars 40 forks source link

Patched weblogic being reported as vulnerable #8

Open arleybls opened 8 years ago

arleybls commented 8 years ago

Have managed to patch few weblogics both 11g and 12c and the script still report them as vulnerable. Can you guys confirm if the detection logic is reliable?

johndekroon commented 7 years ago

You're correct, but there is no reliable way to confirm whether weblogic is patched or not (well, we could run the exploit, but hey, let's not do that :) ).