¡¾Ô­´´·ì϶¡¿Oracle WebLogic Ô¶³ÌºÅÁîÖ´Ðзì϶£¨¼´CVE-2019-2725²¹¶¡Èƹý£©

°ä²¼¹¦·ò 2019-06-17
0x01 ·ìϼûèÊö


2019Äê4ÔÂ26ÈÕ £¬Oracle¹Ù·½°ä²¼ÁËWebLogic wls9-async¼°wls-wsat×é¼þÔ¶³ÌºÅÁîÖ´Ðзì϶µÄ²¹¶¡£¨CVE-2019-2725£© £¬https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html¡£


GA»Æ½ð¼×ADLabµÚÒ»¹¦·ò¶Ô¸Ã²¹¶¡½øÐÐÁËÉî¿Ì×êÑÐ £¬·¢Ïָò¹¶¡´æÔÚ°²È«È±µã £¬ÔڵͰ汾JDKµÄ»·¾³ÖÐÄܹ»±»Èƹýµ¼ÖÂËÁÒâÔ¶³ÌºÅÁîÖ´ÐС£ADLabÒÑÏòOracle¹Ù·½·´À¡ÁËCVE-2019-2725²¹¶¡ÈƹýµÄ·ì϶ £¬²¢µÃµ½Á˹ٷ½¼òÖ±ÈÏ¡£ÓÉÓڸ÷ì϶ÄÜʹ¹¥»÷ÕßÔ¶³ÌÖ´ÐÐËÁÒâºÅÁî £¬Ä¿Ç°¹Ù·½²¹¶¡ÉÐδ°ä²¼ÇÒÒÑÓÐЧ»§Êܵ½ÒÉËÆ¸Ã·ì϶µÄ¹¥»÷ £¬½¨ÒéËùÓÐʹÓÃOracle WebLogicµÄÓû§¾¡¿ì×Ô¶¯²¿ÊðÏàÓ¦·À»¤¡£


0x02 ·ì϶¹¦·òÖá


2019Äê6ÔÂ12ÈÕ £¬ADLab½«·ì϶ÏêÇéÌá½»¸øOracle¹Ù·½£»


2019Äê6ÔÂ14ÈÕ £¬Oracle¹Ù·½È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·½¨¸´¡£


0x03 Ó°Ïì°æ±¾


Oracle WebLogic Server 10.3.6.0


0x04 ·ì϶ÀûÓÃ


²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0 + CVE-2019-2725²¹¶¡


ÀûÓùý³Ì£º

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



0x05 һʱ½â¾ö¹æ»®


¹Ù·½²¹¶¡Ç°µÄһʱ·À»¤£º


ɾ³ýwls9_async_response.war¡¢wls_wsat.war¼°ÓйØÎļþ¼Ð £¬²¢³ÁÆôweblogic·þÎñ¡£


²»ÈÝ_async/*¼°wls-wsat/*´ó¾ÖµÄURLõè¾¶½Ó¼û¡£


ʹÓÃ1.7¼°ÒÔÉϵÄjava°æ±¾ÔËÐÐWebLogic£¨Õë¶ÔĿǰÁ÷´«µÄµÍ°æ±¾JDKÀûÓã©¡£