WeblogicÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-15Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-2546£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2551£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
CVE-2020-2546
WebLogic Server 10.3.6.0.0
WebLogic Server 12.1.3.0.0
CVE-2020-2551
Weblogic Server 10.3.6.0.0
Weblogic Server 12.1.3.0.0
Weblogic Server 12.2.1.3.0
Weblogic Server 12.2.1.4.0
Îó²î¸ÅÊö
WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÐļþ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽ Web Ó¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦Óᣡ£¡£¡£¡£
CVE-2020-2546£º
¹¥»÷ÕßÄܹ»Ê¹ÓÃWeblogic T3ÐÒé¾ÙÐз´ÐòÁл¯Îó²îµÄʹÓôӶøÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
CVE-2020-2551£º
¸ÃÎó²î¿ÉÒÔÈÆ¹ýOracle¹Ù·½ÔÚ2019Äê10Ô·ÝÐû²¼µÄ×îÐÂÇå¾²²¹¶¡¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPÐÒéÔ¶³Ì»á¼ûWeblogic ServerЧÀÍÆ÷ÉϵÄÔ¶³Ì½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬´«Èë¶ñÒâÊý¾Ý£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡЧÀÍÆ÷ȨÏÞ²¢ÔÚδÊÚȨÇéÐÎÏÂÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
Éý¼¶²¹¶¡£¬£¬£¬£¬£¬£¬£¬²Î¿¼oracle¹ÙÍøÐû²¼µÄ²¹¶¡¡£¡£¡£¡£¡£
»º½â²½·¥£º
CVE-2020-2546
ÈôÊDz»ÒÀÀµT3ÐÒé¾ÙÐÐJVMͨѶ£¬£¬£¬£¬£¬£¬£¬½ûÓÃT3ÐÒé:
½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬£¬£¬ÔÚbase_domainÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬£¬£¬½øÈëÇ徲ѡÏî¿¨Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬µã»÷ɸѡÆ÷£¬£¬£¬£¬£¬£¬£¬ÉèÖÃɸѡÆ÷¡£¡£¡£¡£¡£ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔò¿òÖÐÊäÈë 7001 deny t3 t3s ÉúÑÄÉúЧ£¨ÐèÖØÆô£©¡£¡£¡£¡£¡£
CVE-2020-2551
¿Éͨ¹ý¹Ø±ÕIIOPÐÒé¶Ô´ËÎó²î¾ÙÐлº½â¡£¡£¡£¡£¡£²Ù×÷ÈçÏ£º
ÔÚWeblogic¿ØÖÆÌ¨ÖУ¬£¬£¬£¬£¬£¬£¬Ñ¡Ôñ¡°Ð§ÀÍ¡±->¡±AdminServer¡±->¡±ÐÒ顱£¬£¬£¬£¬£¬£¬£¬×÷·Ï¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡¡£¡£¡£¡£¡£²¢ÖØÆôWeblogicÏîÄ¿£¬£¬£¬£¬£¬£¬£¬Ê¹ÉèÖÃÉúЧ¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpujan2020.html


¾©¹«Íø°²±¸11010802024551ºÅ