Restricting Incoming Serialized Java Objects to Oracle WebLogic Server - New with WLS PSUs
(Doc ID 2421487.1)
Last updated on DECEMBER 13, 2024
Applies to:
Oracle WebLogic Server - Version 10.3.6 and laterInformation in this document applies to any platform.
- This document was released with the WLS PSU for Oct 2018.
- This document is expected to be updated with newer PSU releases IF there is something new to communicate. Check back when applying the next PSU and JDK update for any updates.
- For example, January 2019 has an updated block list and updated serialFilterScope. July 2019 and 2020 added block listed items. New dates will be in bold.
Purpose
This document provided information to help in restricting incoming serialized Java objects as part of a security best practice or hardening recommendation for Oracle WebLogic Server (WLS).
Note: This document outlines the WebLogic Server JEP 290 integration introduced by a newer JDK and new Patch Set Update that may prompt seeing the following issue with an application:
Doc ID 2490561.1 - After JDK Update and WebLogic Server PSU - Application is Failing with Error: "java.io.InvalidClassException: filter status: REJECTED"
Details
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Purpose |
Details |
Overview and Security Recommendations |
Restricting Incoming Serialized Java Objects to Oracle WebLogic Server |
JEP 290 JDK Support |
WebLogic Server JEP 290 Default Filter |
Customizing the WebLogic Server JEP 290 Default Filter |
Troubleshooting |
References |