WebLogic |¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-160x00 Îó²î¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
|
WebLogic |
CVE-2020-2801 |
´úÂëÖ´ÐÐ |
ÑÏÖØ |
ÊÇ |
Oracle WebLogic Server : 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 |
|
WebLogic |
CVE-2020-2883 |
´úÂëÖ´ÐÐ |
ÑÏÖØ |
ÊÇ |
|
|
WebLogic |
CVE-2020-2884 |
´úÂëÖ´ÐÐ |
ÑÏÖØ |
ÊÇ |
|
|
WebLogic |
CVE-2020-2915 |
´úÂëÖ´ÐÐ |
ÑÏÖØ |
ÊÇ |
Oracle Coherence : 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 |
0x01 Îó²îÏêÇé
Oracle Fusion Middleware£¨OracleÈÚºÏÖÐÐļþ£©ÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»Ì×ÃæÏòÆóÒµºÍÔÆÇéÐεÄÓªÒµÁ¢ÒìÆ½Ì¨¡£¡£¡£¸Ãƽ̨ÌṩÁËÖÐÐļþ¡¢Èí¼þÜöÝ͵ȹ¦Ð§¡£¡£¡£
2020Äê4ÔÂ15ÈÕ£¬£¬£¬£¬Oracle¹Ù·½Ðû²¼4Ô²¹¶¡¸üÐÂͨ¸æ£¬£¬£¬£¬Åû¶Á˶à¸ö¸ßΣÎó²î¡£¡£¡£ÆäÖаüÀ¨Èý¸öÕë¶ÔWeblogicµÄÑÏÖØÎó²î£¨CVE-2020-2801¡¢CVE-2020-2883¡¢CVE-2020-2884£©ºÍÒ»¸öOracle CoherenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2915£©£¬£¬£¬£¬CVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£
ÉÏÊöËĸöÎó²î¶¼ÓëT3ÐÒé·´ÐòÁл¯Óйء£¡£¡£ÓÉÓÚWeblogic ĬÈÏ¿ªÆô T3ÐÒ飬£¬£¬£¬¹¥»÷Õß½«ÌìÉúµÄpayload·â×°ÔÚT3ÐÒéÖУ¬£¬£¬£¬ÔÚ·´ÐòÁл¯Àú³ÌÖжÔWebLogic×é¼þ¾ÙÐÐÔ¶³Ì´úÂë¹¥»÷£¬£¬£¬£¬»ñȡϵͳȨÏÞ¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2020.html
ÔÝʱ²½·¥£ºÈôÊDz»ÒÀÀµT3ÐÒé¾ÙÐÐJVMͨѶ£¬£¬£¬£¬¿É½ûÓÃT3ÐÒ飬£¬£¬£¬ÏêϸÈçÏ£º
-
½øÈëWeblogic¿ØÖÆÌ¨£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖ㻣»£»£»£»£»£»£»
-
ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔò¿òÖÐÊäÈë 7001 deny t3 t3sÉúÑÄÉúЧ£»£»£»£»£»£»£»£»
-
ÉúÑĺóÈô¹æÔòδÉúЧ£¬£¬£¬£¬½¨ÒéÖØÐÂÆô¶¯WeblogicЧÀÍ¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpuapr2020.html
0x04 ʱ¼äÏß
2020-04-15 Oracle¹Ù·½Ðû²¼Îó²î
2020-04-15 CVEÐû²¼¸ÃÎó²î


¾©¹«Íø°²±¸11010802024551ºÅ