¡¾Ô´´Â©¶´¡¿WebLogic Blind XXE©¶´Í¨¸æ£¨CVE-2020-14820£©
Ðû²¼Ê±¼ä 2020-10-22©¶´¸ÅÊö
Oracle¹Ù·½Ðû²¼ÁË10Ô·ݵÄÄþ¾²²¹¶¡, ²¹¶¡ÖаüÂÞ¶«Éƽ̨ADLab·¢ÏÖ²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄ©¶´£¬Â©¶´±àºÅΪCVE-2020-14820¡£Í¨¹ý¸Ã©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3»òIIOPÐÒéÖУ¬Í¨¹ý¶ÔÐÒéÖеÄpayload½øÐз´ÐòÁл¯£¬´Ó¶øʵÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷¡£
©¶´Ê±¼äÖá
2020Äê5ÔÂ11ÈÕ£¬ADLab½«Â©¶´ÏêÇéÌá½»¸øOracle¹Ù·½£»
2020Äê5ÔÂ12ÈÕ£¬Oracle¹Ù·½È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼×ÅÊÖÐÞ¸´£»
2020Äê10ÔÂ21ÈÕ£¬Oracle¹Ù·½Ðû²¼Äþ¾²²¹¶¡¡£
ÊÜÓ°Ïì°æ±¾
Weblogic 10.3.6.0.0
Weblogic 12.1.3.0.0
Weblogic 12.2.1.3.0
Weblogic 12.2.1.4.0
Weblogic 14.1.1.0.0
©¶´ÀûÓÃ
²âÊÔ»·¾³£ºWebLogicServer 10.3.6.0.0
©¶´ÀûÓÃЧ¹û£º
¹æ±Ü·½°¸
1¡¢Éý¼¶²¹¶¡
https://www.oracle.com/security-alerts/cpuoct2020.html
2¡¢¿ØÖÆT3ÐÒéµÄ·ÃÎÊ
¾ßÌå²Ù×÷£º
1£©½øÈëWebLogic¿ØÖÆ̨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡ÏҳÃ棬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£
2)ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£
3£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£
3¡¢½ûÖ¹ÆôÓÃIIOPÐÒé
µÇ½WebLogic¿ØÖÆ̨£¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer
¶«Éƽ̨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©
DLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´900Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£