WeblogicÔÙ±¬¸ßΣ©¶´ ¶«É­Æ½Ì¨Ìṩ½â¾ö·½°¸

Ðû²¼Ê±¼ä 2019-10-17
2019Äê10ÔÂ15ÈÕ £¬Oracle¹Ù·½Ðû²¼10Ô·ÝÄþ¾²²¹¶¡, ÆäÖаüÂÞÁ˶«É­Æ½Ì¨ADLab·¢ÏÖ²¢Ìá½»¸ø¹Ù·½µÄÁ½¸öÄþ¾²Â©¶´¡£



CVE-2019-2890  £¬¹¥»÷Õß¿Éͨ¹ýT3ЭÒé¶Ô´æÔڸé¶´µÄWebLogic×é¼þʵʩԶ³ÌÈÎÒâ´úÂë¹¥»÷ £»


CVE-2019-2887 £¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ЭÒé¶Ô´æÔڸé¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷¡£


©¶´Ó°Ïì°æ±¾



WebLogic Server 10.3.6.0
WebLogic Server 12.1.3.0
WebLogic Server 12.2.1.3



©¶´ÀûÓÃ



Äþ¾²Â©¶´£ºCVE-2019-2890
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
©¶´ÀûÓÃЧ¹û£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Äþ¾²Â©¶´£ºCVE-2019-2887
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
©¶´ÀûÓÃЧ¹û:  

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



½â¾ö·½°¸



? Éý¼¶¹Ù·½²¹¶¡
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

? ²úÎï¼ì²âÓë·À»¤
ÒѲ¿Êð¶«É­Æ½Ì¨IDS¡¢IPS¡¢WAF²úÎïµÄ¿Í»§ÇëÈ·ÈÏÈçÏÂʼþ¹æÔòÒѾ­Ï·¢²¢Ó¦Óà £¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£º 


TCP_Oracle_WebLogic_·´ÐòÁл¯Â©¶´[CVE-2019-2890] 
HTTP_WebLogic_XXE×¢Èë©¶´[CVE-2019-2887]

£¨1£©ÌìãÙÈëÇÖ¼ì²âÓë¹ÜÀíϵͳ±¨¾¯½ØÍ¼£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

£¨3£©ÌìÇåWebÓ¦ÓÃÄþ¾²Íø¹Ø±¨¾¯½ØÍ¼£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


©¶´É¨Ãè


¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0ÓÚ2019Äê10ÔÂ17ÈÕ½ô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸Ã©¶´½øÐмì²â £¬Óû§Éý¼¶Ì쾵©ɨ²úÎï©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃè¡£


6070°æ±¾Éý¼¶°üΪ607000250 £¬Éý¼¶°üÏÂÔØµØÖ·£º
/article/type/1/146.html

ÇëÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â £¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾