9.8·Ö & 7.2·Ö 8827Ì«Ñô¼¯ÍÅΪCVE¸ß·Ö·ì϶Ìṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2020-04-17Oracle¹Ù·½°ä²¼4Ô·ݰ²È«²¹¶¡, ²¹¶¡ÖÐÔ̺¬8827Ì«Ñô¼¯ÍÅADLab·¢ÏÖ²¢µÚÒ»¹¦·òÌá½»¸ø¹Ù·½µÄ·ì϶£¬£¬£¬£¬£¬£¬·ì϶±àºÅΪCVE-2020-2798ºÍCVE-2020-2801¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2020-2798 CVVSÆÀ·ÖΪ7.2·Ö£¬£¬£¬£¬£¬£¬CVE-2020-2801·ì϶µÈ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬£¬CVVSÆÀ·ÖΪ9.8·Ö¡£¡£¡£¡£¡£¡£¡£
·ì϶¶¼ÓëT3ºÍ̸·´ÐòÁл¯Óйأ¬£¬£¬£¬£¬£¬ÀûÓ÷ì϶¹¥»÷Õß½«ÌìÉúµÄpayload·â×°ÔÚT3ºÍ̸ÖУ¬£¬£¬£¬£¬£¬ÔÚ·´ÐòÁл¯¹ý³ÌÖÐʵÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌËÁÒâ´úÂë¹¥»÷¡£¡£¡£¡£¡£¡£¡£
·ì϶ÀûÓÃ
CVE-2020-2798
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ£º
CVE-2020-2798
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ£º
·ì϶ӰÏì°æ±¾
Weblogic 10.3.6.0
Weblogic 12.1.3.0
Weblogic 12.2.1.3
Weblogic 12.2.1.4
½â¾ö¹æ»®
Éý¼¶²¹¶¡
https://www.oracle.com/security-alerts/cpuapr2020.htm
½ÚÔìT3ºÍ̸µÄ½Ó¼û
·ì϶²úÉúÓÚWeblogicµÄT3·þÎñ£¬£¬£¬£¬£¬£¬Òò¶ø¿Éͨ¹ý½ÚÔìT3ºÍ̸µÄ½Ó¼ûÀ´Ò»Ê±×è¶ÏÕë¶Ô·ì϶µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£µ±Ê¢¿ªWeblogic½ÚÔì´ó¼Ý¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê±£¬£¬£¬£¬£¬£¬T3·þÎñ»áĬÈÏ¿ªÆô¡£¡£¡£¡£¡£¡£¡£
¾ßÌå²Ù×÷£º
1£©½øÈëWebLogic½ÚÔį̀£¬£¬£¬£¬£¬£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬£¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬£¬½øÈëÏνÓɸѡÆ÷ÅäÖᣡ£¡£¡£¡£¡£¡£
2£©ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬£¬£¬£¬£¬£¬0.0.0.0/0 * * deny t3 t3s£¨t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û£©¡£¡£¡£¡£¡£¡£¡£
3£©±£ÁôºóÐè³ÁÐÂÆô¶¯£¬£¬£¬£¬£¬£¬¹æ¶¨·½¿ÉÉúЧ¡£¡£¡£¡£¡£¡£¡£
²úÆ·¼ì²âÓë·À»¤
ÒѲ¿Êð8827Ì«Ñô¼¯ÍÅIDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾÏ·¢²¢ÀûÓ㬣¬£¬£¬£¬£¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£º
TCP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-2798]
TCP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-2801
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
£¨3£©ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º


¾©¹«Íø°²±¸11010802024551ºÅ