Oracle Access Manager ADF Faces Deserialization Vulnerability Remote Code Execution Exploit

This module exploits a server side request forgery present in getKeyInfoData function of oracle.security.xmlsec.keys.RetrievalMethod. Chained with a deserialization vulnerability present in the ADF Faces framework to deploy an agent in the system running Oracle Access Manager.
Exploit Platform
Product Name