¡¾Ô´´Â©¶´¡¿WebLogic ·´ÐòÁл¯RCE©¶´Í¨¸æ£¨CVE-2021-2135£©
Ðû²¼Ê±¼ä 2021-04-22©¶´¸ÅÊö
Oracle¹Ù·½Ðû²¼ÁË4Ô·ݵÄÄþ¾²²¹¶¡, ²¹¶¡ÖаüÂÞ¶«Éƽ̨ADLab·¢ÏÖ²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄ©¶´£¬Â©¶´±àºÅΪCVE-2021-2135¡£Â©¶´Æ·¼¶Îª¸ßΣ£¬CVVSÆÀ·ÖΪ9.8·Ö¡£¸Ã©¶´´æÔÚÓÚWebLogicT3ÐÒé»òIIOPÐÒéµÄͨÐŹý³ÌÖУ¬Í¨¹ý¸Ã©¶´£¬¹¥»÷Õß½«Éú³ÉµÄpayload·â×°ÔÚT3ÐÒé»òIIOPÐÒéÖУ¬ÔÚ·´ÐòÁл¯¹ý³ÌÖÐʵÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þµÄÔ¶³ÌÈÎÒâ´úÂëÖ´Ðй¥»÷¡£
©¶´Ê±¼äÖá
2021Äê2Ô£¬½«Â©¶´ÏêÇéÌá½»¸ø¹Ù·½£»
2021Äê3Ô£¬È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼×ÅÊÖÐÞ¸´£»
2021Äê4ÔÂ21ÈÕ£¬¹Ù·½Ðû²¼Õýʽ²¹¶¡¡£
Ó°Ïì°æ±¾
Weblogic 12.1.3.0.0
Weblogic 12.2.1.3.0
Weblogic 12.2.1.4.0
Weblogic 14.1.1.0.0
ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾
©¶´ÀûÓÃ
²âÊÔ»·¾³£ºWeblogic Server 12.2.1.3
©¶´ÀûÓÃЧ¹û£º
¹æ±Ü·½°¸
1¡¢Éý¼¶²¹¶¡
https://www.oracle.com/security-alerts/cpuapr2021.html
2¡¢¿ØÖÆT3ÐÒéµÄ·ÃÎÊ
´Ë©¶´·¢ÉúÓÚWebLogicµÄT3·þÎñ£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ·ÃÎÊÀ´ÁÙʱ×è¶ÏÕë¶Ô¸Ã©¶´µÄ¹¥»÷¡£µ±¿ª·ÅWebLogic¿ØÖÆ̨¶Ë¿Ú£¨Ä¬ÈÏΪ7001¶Ë¿Ú£©Ê±£¬T3·þÎñ»áĬÈÏ¿ªÆô¡£
¾ßÌå²Ù×÷£ºa£©½øÈëWebLogic¿ØÖÆ̨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡ÏҳÃ棬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£
b£©ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬0.0.0.0/0 * * deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£
c£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£
¶«Éƽ̨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£