¡¾Ô´´·ì϶¡¿Weblogic ·´ÐòÁл¯·ì϶¹«¸æ£¨CVE-2020-2798 ¡¢¡¢¡¢CVE-2020-2801£©
°ä²¼¹¦·ò 2020-04-15·ì϶¸ÅÊö
Oracle¹Ù·½°ä²¼4Ô·ݰ²È«²¹¶¡, ²¹¶¡ÖÐÔ̺¬OG¶«·½ÌüADLab·¢ÏÖ²¢µÚÒ»¹¦·òÌá½»¸ø¹Ù·½µÄ·ì϶£¬£¬£¬·ì϶±àºÅΪCVE-2020-2798ºÍCVE-2020-2801¡£¡£¡£ÆäÖУ¬£¬£¬CVE-2020-2798 CVVSÆÀ·ÖΪ7.2·Ö£¬£¬£¬CVE-2020-2801·ì϶µÈ¼¶Îª¸ßΣ£¬£¬£¬CVVSÆÀ·ÖΪ9.8·Ö¡£¡£¡£
CVE-2020-2798ºÍCVE-2020-2801·ì϶¶¼ÓëT3ºÍ̸·´ÐòÁл¯Óйأ¬£¬£¬ÀûÓ÷ì϶¹¥»÷Õß½«ÌìÉúµÄpayload·â×°ÔÚT3ºÍ̸ÖУ¬£¬£¬ÔÚ·´ÐòÁл¯¹ý³ÌÖÐʵÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌËÁÒâ´úÂë¹¥»÷¡£¡£¡£
·ì϶¹¦·òÖá
2019Äê12Ô£¬£¬£¬ADLab½«·ì϶ÏêÇéÌá½»¸øOracle¹Ù·½£»
2020Äê1ÔÂ6ÈÕ£¬£¬£¬Oracle¹Ù·½È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·×ÅÊÖÐÞ¸´£»
2020Äê4ÔÂ14ÈÕ£¬£¬£¬Oracle¹Ù·½°ä²¼°²È«²¹¶¡¡£¡£¡£
·ì϶ӰÏì°æ±¾
Weblogic 10.3.6.0
Weblogic 12.1.3.0
Weblogic 12.2.1.3
Weblogic 12.2.1.4
ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£¡£¡£
·ì϶ÀûÓÃ
1¡¢¡¢¡¢CVE-2020-2798
²âÊÔ»·¾³£º£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ£º£º
2¡¢¡¢¡¢CVE-2020-2798
²âÊÔ»·¾³£º£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ£º£º
¶ã±Ü¹æ»®
1¡¢¡¢¡¢Éý¼¶²¹¶¡
https://www.oracle.com/security-alerts/cpuapr2020.html
2¡¢¡¢¡¢½ÚÖÆT3ºÍ̸µÄ½Ó¼û
·ì϶²úÉúÓÚWeblogicµÄT3·þÎñ£¬£¬£¬Òò¶ø¿Éͨ¹ý½ÚÖÆT3ºÍ̸µÄ½Ó¼ûÀ´Ò»Ê±×è¶ÏÕë¶Ô·ì϶µÄ¹¥»÷¡£¡£¡£µ±Ê¢¿ªWeblogic½ÚÖÆ´ó¼Ý¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê±£¬£¬£¬T3·þÎñ»áĬÈÏ¿ªÆô¡£¡£¡£
¾ßÌå²Ù×÷£º£º
1£©½øÈëWebLogic½ÚÖÆÌ¨£¬£¬£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬£¬£¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬½øÈëÏνÓɸѡÆ÷ÅäÖᣡ£¡£
2£©ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺£ºweblogic.security.net.ConnectionFilterImpl£¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺£º127.0.0.1 * * allow t3 t3s£¬£¬£¬0.0.0.0/0 * * deny t3 t3s£¨t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û£©¡£¡£¡£
3£©±£ÁôºóÐèÖØÐÂÆô¶¯£¬£¬£¬¹æ¶¨·½¿ÉÉúЧ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ