WebLogic |¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-160x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
WebLogic |
CVE-2020-2801 |
´úÂëÖ´ÐÐ |
ÑϳÁ |
ÊÇ |
Oracle WebLogic Server : 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 |
|
WebLogic |
CVE-2020-2883 |
´úÂëÖ´ÐÐ |
ÑϳÁ |
ÊÇ |
|
|
WebLogic |
CVE-2020-2884 |
´úÂëÖ´ÐÐ |
ÑϳÁ |
ÊÇ |
|
|
WebLogic |
CVE-2020-2915 |
´úÂëÖ´ÐÐ |
ÑϳÁ |
ÊÇ |
Oracle Coherence : 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 |
0x01 ·ì϶ÏêÇé
Oracle Fusion Middleware£¨OracleÈÚºÏÖÐÑë¼þ£©ÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»Ì×ÃæÏòÆóÒµºÍÔÆ»·¾³µÄÒµÎñ´´ÐÂÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨ÌṩÁËÖÐÑë¼þ¡¢Èí¼þ¼¯ÖеÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£
2020Äê4ÔÂ15ÈÕ£¬£¬£¬£¬£¬Oracle¹Ù·½°ä²¼4Ô²¹¶¡¸üв¼¸æ£¬£¬£¬£¬£¬Åû¶Á˶à¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬Èý¸öÕë¶ÔWeblogicµÄÑϳÁ·ì϶£¨CVE-2020-2801¡¢CVE-2020-2883¡¢CVE-2020-2884£©ºÍÒ»¸öOracle CoherenceÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-2915£©£¬£¬£¬£¬£¬CVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£¡£¡£¡£¡£
ÉÏÊöËĸö·ì϶¶¼ÓëT3ºÍ̸·´ÐòÁл¯Óйء£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚWeblogic ĬÈÏ¿ªÆô T3ºÍ̸£¬£¬£¬£¬£¬¹¥»÷Õß½«ÌìÉúµÄpayload·â×°ÔÚT3ºÍ̸ÖУ¬£¬£¬£¬£¬ÔÚ·´ÐòÁл¯¹ý³ÌÖжÔWebLogic×é¼þ½øÐÐÔ¶³Ì´úÂë¹¥»÷£¬£¬£¬£¬£¬»ñȡϵͳȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2020.html
һʱ´ëÊ©£ºÈôÊDz»ÒÀÀµT3ºÍ̸½øÐÐJVMͨѶ£¬£¬£¬£¬£¬¿É½ûÓÃT3ºÍ̸£¬£¬£¬£¬£¬¾ßÌåÈçÏ£º
-
½øÈëWeblogic½ÚÔį̀£¬£¬£¬£¬£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬½øÈëÏνÓɸѡÆ÷ÅäÖ㻣»£»£»£»£»£»£»
-
ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨¿òÖÐÊäÈë 7001 deny t3 t3s±£ÁôÉúЧ£»£»£»£»£»£»£»£»
-
±£ÁôºóÈô¹æ¶¨Î´ÉúЧ£¬£¬£¬£¬£¬½¨Òé³ÁÐÂÆô¶¯Weblogic·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpuapr2020.html
0x04 ¹¦·òÏß
2020-04-15 Oracle¹Ù·½°ä²¼·ì϶
2020-04-15 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ