¡¾Ô­´´·ì϶¡¿Oracle WebLogic Ô¶³ÌºÅÁîÖ´Ðзì϶£¨¼´CVE-2019-2725²¹¶¡Èƹý£©

°ä²¼¹¦·ò 2019-06-17
0x01 ·ì϶ÃèÊö


2019Äê4ÔÂ26ÈÕ£¬£¬Oracle¹Ù·½°ä²¼ÁËWebLogic wls9-async¼°wls-wsat×é¼þÔ¶³ÌºÅÁîÖ´Ðзì϶µÄ²¹¶¡£¡£¡£¨CVE-2019-2725£©£¬£¬https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html¡£¡£¡£


OG¶«·½ÌüADLabµÚÒ»¹¦·ò¶Ô¸Ã²¹¶¡½øÐÐÁËÉî¿Ì×êÑУ¬£¬·¢Ïָò¹¶¡´æÔÚ°²È«È±µã£¬£¬ÔڵͰ汾JDKµÄ»·¾³ÖÐÄܹ»±»Èƹýµ¼ÖÂËÁÒâÔ¶³ÌºÅÁîÖ´ÐС£¡£¡£ADLabÒÑÏòOracle¹Ù·½·´À¡ÁËCVE-2019-2725²¹¶¡ÈƹýµÄ·ì϶£¬£¬²¢µÃµ½Á˹ٷ½¼òÖ±ÈÏ¡£¡£¡£ÓÉÓڸ÷ì϶ÄÜʹ¹¥»÷ÕßÔ¶³ÌÖ´ÐÐËÁÒâºÅÁ£¬Ä¿Ç°¹Ù·½²¹¶¡ÉÐδ°ä²¼ÇÒÒÑÓÐЧ»§Êܵ½ÒÉËÆ¸Ã·ì϶µÄ¹¥»÷£¬£¬½¨ÒéËùÓÐʹÓÃOracle WebLogicµÄÓû§¾¡¿ì×Ô¶¯²¿ÊðÏàÓ¦·À»¤¡£¡£¡£


0x02 ·ì϶¹¦·òÖá


2019Äê6ÔÂ12ÈÕ£¬£¬ADLab½«·ì϶ÏêÇéÌá½»¸øOracle¹Ù·½£»£»


2019Äê6ÔÂ14ÈÕ£¬£¬Oracle¹Ù·½È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·ÐÞ¸´¡£¡£¡£


0x03 Ó°Ïì°æ±¾


Oracle WebLogic Server 10.3.6.0


0x04 ·ì϶ÀûÓÃ


²âÊÔ»·¾³£º£º£ºWebLogic Server 10.3.6.0 + CVE-2019-2725²¹¶¡


ÀûÓùý³Ì£º£º£º

OG¶«·½Ìü¡¤(Öйú´ó½)



0x05 һʱ½â¾ö¹æ»®


¹Ù·½²¹¶¡Ç°µÄһʱ·À»¤£º£º£º


ɾ³ýwls9_async_response.war¡¢¡¢wls_wsat.war¼°ÓйØÎļþ¼Ð£¬£¬²¢ÖØÆôweblogic·þÎñ¡£¡£¡£


²»ÈÝ_async/*¼°wls-wsat/*´ó¾ÖµÄURLõè¾¶½Ó¼û¡£¡£¡£


ʹÓÃ1.7¼°ÒÔÉϵÄjava°æ±¾ÔËÐÐWebLogic£¨Õë¶ÔĿǰÁ÷´«µÄµÍ°æ±¾JDKÀûÓã©¡£¡£¡£