¡¾Ô´´·ì϶¡¿Oracle WebLogic Ô¶³ÌºÅÁîÖ´Ðзì϶£¨¼´CVE-2019-2725²¹¶¡Èƹý£©
°ä²¼¹¦·ò 2019-06-172019Äê4ÔÂ26ÈÕ£¬£¬Oracle¹Ù·½°ä²¼ÁËWebLogic wls9-async¼°wls-wsat×é¼þÔ¶³ÌºÅÁîÖ´Ðзì϶µÄ²¹¶¡£¡£¡£¨CVE-2019-2725£©£¬£¬https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html¡£¡£¡£
0x02 ·ì϶¹¦·òÖá
2019Äê6ÔÂ12ÈÕ£¬£¬ADLab½«·ì϶ÏêÇéÌá½»¸øOracle¹Ù·½£»£»
0x03 Ó°Ïì°æ±¾
Oracle WebLogic Server 10.3.6.0
0x04 ·ì϶ÀûÓÃ
²âÊÔ»·¾³£º£º£ºWebLogic Server 10.3.6.0 + CVE-2019-2725²¹¶¡
¹Ù·½²¹¶¡Ç°µÄһʱ·À»¤£º£º£º
ɾ³ýwls9_async_response.war¡¢¡¢wls_wsat.war¼°ÓйØÎļþ¼Ð£¬£¬²¢ÖØÆôweblogic·þÎñ¡£¡£¡£
²»ÈÝ_async/*¼°wls-wsat/*´ó¾ÖµÄURLõè¾¶½Ó¼û¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ