Oracle¶à¸ö²úÆ·°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-07-15

0x00 ·ì϶¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

WebLogic

CVE-2020-14625

ÑϳÁ

ÊÇ

WebLogic 12.2.1.3.0

WebLogic 12.2.1.4.0

WebLogic 14.1.1.0.0

CVE-2020-14644

ÑϳÁ

ÊÇ

CVE-2020-14687

ÑϳÁ

ÊÇ

CVE-2020-14645

ÑϳÁ

ÊÇ

WebLogic 10.3.6.0.0

WebLogic 12.1.3.0.0

WebLogic 12.2.1.3.0

WebLogic 12.2.1.4.0

WebLogic 14.1.1.0.0

Oracle SD-WAN Aware

CVE-2020-14701

ÑϳÁ

ÊÇ

Oracle SD-WAN Aware 8.2

Oracle SD-WAN Edge

CVE-2020-14606

ÑϳÁ

ÊÇ

Oracle SD-WAN Edge 8.2,9.0



0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2020Äê7ÔÂ14ÈÕ£¬£¬£¬ £¬£¬£¬Oracle¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬ £¬£¬£¬½¨¸´ÁË433¸ö°²È«·ì϶£¬£¬£¬ £¬£¬£¬Éæ¼°ÁËOracle Weblogic¡¢Oracle CoherenceµÈ¶à¿î²úÆ·¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬ËĸöÆÀ·ÖΪ9.8µÄOracle WebLogic Server·´ÐòÁл¯·ì϶£¨CVE-2020-14625¡¢CVE-2020-14644¡¢CVE-2020-14645 ¡¢CVE-2020-14687£©£¬£¬£¬ £¬£¬£¬Á½¸öÆÀ·ÖΪ10µÄOracle Communications Applications°²È«·ì϶£¨CVE-2020-14701¡¢CVE-2020-14606£©¡£¡£¡£¡£¡£¡£

Oracle WebLogic Server·´ÐòÁл¯·ì϶

ÕâËĸö·ì϶µ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýIIOP¡¢T3ºÍ̸·¢ËͶñÒâÒªÇ󣬣¬£¬ £¬£¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£

Oracle Communications Applications°²È«·ì϶

ÕâÁ½¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼²¹¶¡£¬£¬£¬ £¬£¬£¬ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpujul2020.html

Weblogicһʱ½¨²¹½¨Ò飺

1. ÈôÊDz»ÒÀÀµT3ºÍ̸½øÐÐJVMͨѶ£¬£¬£¬ £¬£¬£¬½ûÓÃT3ºÍ̸¡£¡£¡£¡£¡£¡£

? ½øÈëWebLogic½ÚÔį̀£¬£¬£¬ £¬£¬£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬£¬£¬ £¬£¬£¬½øÈ밲ȫѡÏî¿¨Ò³Ãæ£¬£¬£¬ £¬£¬£¬µã»÷ɸѡÆ÷£¬£¬£¬ £¬£¬£¬ÅäÖÃɸѡÆ÷£»£»£»£»£»£»£»£»

? ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬ £¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨¿òÖÐÊäÈë 7001 deny t3 t3s±£ÁôÉúЧ£»£»£»£»£»£»£»£»

? ³ÁÆôWeblogicÏîÄ¿£¬£¬£¬ £¬£¬£¬Ê¹ÅäÖÃÉúЧ¡£¡£¡£¡£¡£¡£

2. ÈôÊDz»ÒÀÀµIIOPºÍ̸½øÐÐJVMͨѶ£¬£¬£¬ £¬£¬£¬½ûÓÃIIOPºÍ̸¡£¡£¡£¡£¡£¡£

? ½øÈëWebLogic½ÚÔį̀£¬£¬£¬ £¬£¬£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬£¬£¬ £¬£¬£¬½øÈ밲ȫѡÏî¿¨Ò³Ãæ£»£»£»£»£»£»£»£»

? Ñ¡Ôñ¡°·þÎñ¡±->¡±AdminServer¡±->¡±ºÍ̸¡±£¬£¬£¬ £¬£¬£¬È¡µÞ¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»

? ³ÁÆôWeblogicÏîÄ¿£¬£¬£¬ £¬£¬£¬Ê¹ÅäÖÃÉúЧ¡£¡£¡£¡£¡£¡£


0x03 ÓйØÐÂÎÅ


0x04 ²Î¿¼Á´½Ó


https://www.oracle.com/security-alerts/cpujul2020.html


0x05 ¹¦·òÏß


2020-07-14 Oracle¹Ù·½°ä²¼°²È«²¼¸æ

2020-07-15 VSRC°ä²¼·ì϶¹«¸æ



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website