Coalfire-Research/java-deserialization-exploits

Where to download the vulnerable version of websphere

mudongliang opened this issue · 1 comments

I google for the vulnerable version of websphere, but found no result. If you know where to download this vulnerable version, could you please tell me?

wow well I apologize for the delay.

To answer your question, you can download the vulnerable version of websphere here https://www-01.ibm.com/marketing/iwm/iwm/web/preLogin.do?lang=en_US&source=swg-wsasfd&S_CMP=web_dw_rt_swd

(you're going to need a valid IBM account to access the link)

It actually took us longer to figure out where to download it than making the exploit :/