¡¾Ô´´Â©¶´¡¿WebLogic ·´ÐòÁл¯Â©¶´£¨CVE-2019-2890£©
Ðû²¼Ê±¼ä 2019-10-16©¶´¸ÅÊö
2019Äê10ÔÂ15ÈÕ£¬Oracle¹Ù·½Ðû²¼10Ô·ÝÄþ¾²²¹¶¡, ²¹¶¡ÖаüÂÞ¶«Éƽ̨ADLab·¢ÏÖ²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄ©¶´£¬Â©¶´±àºÅΪCVE-2019-2890¡£ÀûÓø鶴£¬¹¥»÷Õß¿Éͨ¹ýT3ÐÒé¶Ô´æÔÚ©¶´µÄWebLogic×é¼þʵʩԶ³ÌÈÎÒâ´úÂë¹¥»÷¡£
©¶´Ê±¼äÖá
2019Äê5ÔÂ7ÈÕ£¬ADLab½«Â©¶´ÏêÇéÌá½»¸øOracle¹Ù·½£»
2019Äê5ÔÂ25ÈÕ£¬Oracle¹Ù·½È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼×ÅÊÖÐÞ¸´£»
2019Äê10ÔÂ15ÈÕ£¬Oracle¹Ù·½·ÖÅäCVE±àºÅ²¢Ðû²¼Äþ¾²²¹¶¡¡£
©¶´Ó°Ïì°æ±¾
WebLogic Server 10.3.6.0
WebLogic Server 12.1.3.0
WebLogic Server 12.2.1.3
ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£
©¶´ÀûÓÃ
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
©¶´ÀûÓÃЧ¹û
¹æ±Ü·½°¸
1¡¢Éý¼¶²¹¶¡
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2¡¢¿ØÖÆT3ÐÒéµÄ·ÃÎÊ
´Ë©¶´·¢ÉúÓÚWebLogicµÄT3·þÎñ£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ·ÃÎÊÀ´ÁÙʱ×è¶ÏÕë¶Ô¸Ã©¶´µÄ¹¥»÷¡£µ±¿ª·ÅWebLogic¿ØÖÆ̨¶Ë¿Ú£¨Ä¬ÈÏΪ7001¶Ë¿Ú£©Ê±£¬T3·þÎñ»áĬÈÏ¿ªÆô¡£
¾ßÌå²Ù×÷£º
a£©½øÈëWebLogic¿ØÖÆ̨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡ÏҳÃ棬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£
b£©ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s,0.0.0.0/0 * * deny t3 t3s£¨t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ£©¡£
c£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£