2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·£»Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©
°ä²¼¹¦·ò 2020-02-211.ÖйúÈËÃñÒøÐа䲼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·
ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶>ÐÐÒµ³ß¶ÈµÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬°ä²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·(JR/T 0068-2020)£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄ´úÌæ¶©Õý°æ±¾¡£ÐÂ°æ¹æ·¶ÓÐÈý¸ö³Áµã¶©ÕýÄÚÈÝ£º1¡¢Õë¶Ôм¼Êõ³öÏÖºÍÀûÓÃÌá³öÁËÐµİ²È«ÒªÇó£¨ÀýÈçÔö³¤ÁËÐé¹¹»¯¡¢ÔÆÍÆË㰲ȫÓйØÒªÇó£¬Ôö³¤¹úÃÜSMϵÁÐËã·¨ÓйصݲȫҪÇó£¬Ôö³¤¶Ô°²È«µ¥ÔªºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅ»·¾³ÓйØÒªÇ󣩣»2¡¢¾ÍеÄÒµÎñºÍ¼à¹ÜÒªÇó½øÐÐÁ˲¹³äºÍÃ÷È·£¨ÀýÈçÔö³¤ÁËÌõÂëÖ§¸¶¡¢ÂòÂô°²È«ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÓйØÒªÇ󣩣»3¡¢³ÁÐÂÊáÀí²¢ÌáÉý¹ØÓÚÒµÎñÂ½ÐøÐÔÓë¿àÄѸ´Ô¡¢°²È«ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄ°²È«ÒªÇó¡£
ÔÎÄÁ´½Ó£º
https://www.cebnet.com.cn/20200219/102639904.html
2.˼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷ÌØÈ¨ÕË»§ºÍ¾²Ì¬ÃÜÂ룬½¨ÒéÂíÉϽ¨¸´
˼¿Æ½¨¸´ÆäÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM£©ÖеÄÌØÈ¨ÕË»§¾²Ì¬ÃÜÂë·ì϶£¬¸Ã·ì϶£¨CVE-2020-3158£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬Ëü¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÈ¨½Ï¸ßµÄÕÊ»§½Ó¼ûϵͳµÄÃô¸Ð²¿ÃÅ¡£Ë¼¿Æ°µÊ¾£¬¡°¸Ã·ì϶ÊÇÓÉÓÚijϵͳÕË»§ÓµÓÐĬÈϺ;²Ì¬ÃÜÂëÇÒ²¢²»ÊÜϵͳÖÎÀíÔ±½ÚÔì¶øÔì³ÉµÄ¡£¡±SSM On-PremϵͳֻÓÐÔÚÆôÓÃÁ˸߿ÉÓÃÐÔ£¨HA£©Ö°ÄÜʱ²ÅÒ×Êܹ¥»÷£¬µ«¸ÃÖ°ÄÜĬÈÏδÆôÓá£Ë¼¿ÆÖÒ¸æ³Æ£¬¹¥»÷Õß²»±ØÒªÓÐЧµÄµÇ¼¾ÍÄܹ»ÌáÒé¹¥»÷£¬²¢ÇÒÄܹ»Ê¹ÓøßÌØÈ¨Ä¬ÈÏÕÊ»§À´ÏνÓÒ×Êܹ¥»÷µÄϵͳ£¬»ñµÃ¶ÔϵͳÊý¾ÝµÄ¶Áд½Ó¼ûȨÏÞ£¬²¢¸ü¸ÄÆäÉèÖá£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cisco-critical-bug-static-password-in-smart-software-manager-patch-now-says-cisco/
3.Adobe°ä²¼´¹Î£°²È«¸üУ¬½¨¸´Á½¸ö´úÂëÖ´Ðзì϶
Adobe°ä²¼´¹Î£°²È«¸üУ¬½¨¸´Æä²úÆ·ÖеÄÁ½¸ö´úÂëÖ´Ðзì϶¡£µÚÒ»¸ö·ì϶£¨CVE-2020-3764£©Êǿɵ¼ÖÂËÁÒâ´úÂëÖ´ÐеÄÔ½½çд·ì϶£¬¸Ã·ì϶ӰÏìÁËWindowsƽ̨ÉϵÄAdobe Media Encoder 14.0¼°¸üÔç°æ±¾¡£µÚ¶þ¸ö·ì϶£¨CVE-2020-3765£©Ò²ÊÇÓÉÔ½½çдµ¼ÖµĴúÂëÖ´Ðзì϶£¬µ«¹¥»÷Ö»ÄÜÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖнøÐУ¬¸Ã·ì϶ӰÏìÁËWindowsƽ̨ÉϵÄAdobe After Effects°æ±¾16.1.2¼°¸üÔç°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-releases-out-of-schedule-fixes-for-critical-vulnerabilities/
4.Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©
Apache Tomcat·þÎñÆ÷´æÔÚÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶¶ÁÈ¡»òÔ̺¬TomcatÉÏËùÓÐwebappĿ¼ÏµÄËÁÒâÎļþ£¬È磺webappÅäÖÃÎļþ»òÔ´´úÂëµÈ¡£¸Ã·ì϶ÓëTomcat AJPºÍ̸Óйأ¬Tomcat AJP ConnectorĬÈÏÅäÖÃϼ´Îª¿ªÆô״̬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¸Ã·ì϶ӰÏìÁËTomcat 6/7/8/9È«°æ±¾£¬Apache¹Ù·½ÒѰ䲼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´Ë·ì϶½øÐн¨¸´£¬½¨ÒéÓû§ÏÂÔØÊ¹Óá£ÓÉÓÚTomcat 6ÒѾÖÕ³¡ÊØ»¤£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâ·ê¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487
5.ÃÀ¹ú²ÎÒéÔ±Ìá³öÐÂÊý¾Ý±£»¤·¨°¸£¬½¨Òé³ÉÁ¢Êý¾Ý±£»¤¾Ö
ÃÀ¹úŦԼÖݲÎÒéÔ±¼ª¶û˹²¼À¼µÂ£¨Kirsten Gillibrand£©ÉÏÖܰ䲼ÁËÒ»ÏîÁ¢·¨²Ý°¸£¬¸Ã·¨°¸½«³ÉÁ¢Ò»¸ö¶ÀÁ¢µÄÁª¹ú»ú¹¹£¬¼´Êý¾Ý±£»¤¾Ö£¬Ö¼ÔÚ½ç˵¡¢ÖٲúÍÖ´ÐÐÊý¾Ý±£»¤¹æ¶¨¡£Õâλ²ÎÒéÔ±ÒÔΪ£¬¡¶Áª¹úÒµÎñίԱ»á·¨¡·²¢Î´½â¾öÊý¾Ý±£»¤·½ÃæµÄÌôÕ½£¬¶øÃÀ¹úÔÚÓ¦¶ÔÊý¾Ý±£»¤ÌôÕ½ºÍÊý×ÖʱÆÚµÄºÜ¶àÆäËüÌôÕ½·½ÃæÂäºó£¬ÃÀ¹úҲûÓÐÒ»¸öרÃŵĻú¹¹À´Ö´ÐÐÊý¾ÝÒþÖԹ涨¡£ÈôÊǸ÷¨°¸»ñµÃͨ¹ý£¬½«ºÏÓÃÓÚÈκÎÊÕÈ볬¹ý2500ÍòÃÀÔª£¬»òÖÎÀí5Íò»ò¸ü¶àÈ˵ÄÓ×ÎÒÊý¾ÝµÄ¹«Ë¾¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/us-senator-proposes-new-data-protection-bill-37232e0b
6.¸çÂ×±ÈÑÇCommunity CareÔâÀÕË÷¹¥»÷£¬»¼ÕßÊý¾Ý¿ÉÄÜй¶
¸çÂ×±ÈÑÇÊ×¶¼µØÓò×î´óµÄ¶ÀÁ¢Ò½ÁÆ»ú¹¹Community Care»¼ÕßÊý¾Ý¿ÉÄÜй¶£¬¸ÃÊÂÎñÊÇÓÉÆä¹ÜÕÊʦÊÂÎñËùBSTÔâµ½ÀÕË÷Èí¼þ¹¥»÷µ¼Öµġ£BSTÓÚ2019Äê12ÔÂ7ÈÕ·¢ÏÖÔ̺¬¿Í»§¹ÜÕʺÍ˰ÊÕÊý¾ÝÔÚÄڵIJ¿ÃÅÍøÂçϰȾÁËÀÕË÷²¡¶¾£¬µ«¸Ã¹«Ë¾¿ÉÄÜʹÓñ¸·Ý»¹ÔÎļþ¡£ÔÚÖ®ºóµÄµ÷²éÖУ¬¸Ã¹«Ë¾ÓÚ2ÔÂ5ÈÕÈ·Èϲ¿ÃÅ»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶£¬ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢Ìõ¿îºÅÂëºÍÕʵ¥´úÂ룬µ«²»Ô̺¬ÒøÐÐÕʺš¢Éç»á°²È«ºÅÂëºÍ²¡ÀúÐÅÏ¢¡£BST»òCommunity Care¶¼Ã»ÓÐй©ÊÜÓ°ÏìµÄ»¼ÕßÈËÊý¡£
ÔÎÄÁ´½Ó£º
https://dailygazette.com/article/2020/02/19/data-breach-community-Care-physicians


¾©¹«Íø°²±¸11010802024551ºÅ