WebLogic ËÁÒâÎļþÉÏ´«Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-19
·ì϶±àºÅºÍ¼¶±ð

CVE-2018-2894  ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
WebLogic 10.3.6.0
WebLogic 12.1.3.0
WebLogic 12.2.1.2

WebLogic 12.2.1.3


·ì϶¸ÅÊö
Oracle¹Ù·½°ä²¼ÁË7Ô·ݵĹؼü²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬ÆäÖÐÕë¶Ô¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐеĸßΣ·ì϶ CVE-2018-2894 ½øÐн¨¸´£ºhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html¡£
½ñÌì7ÔÂ19ºÅ¹ú¶È»¥ÁªÍøÓ¦¼±ÖÐÐÄCNCERT·¢³ö¹«¸æ£¬Ö¸³öCVE-2018-2894ÐÔÖÊÉÏΪËÁÒâÎļþÉÏ´«·ì϶£ºhttps://mp.weixin.qq.com/s/y5JGmM-aNaHcs_6P9a-gRQ¡£
WebLogicÖÎÀí¶ËδÊÚȨµÄÁ½¸öÒ³Ãæ´æÔÚËÁÒâÉÏ´«getshell·ì϶£¬¿ÉÖ±½Ó»ñȡȨÏÞ¡£Á½¸öÒ³Ãæ±ðÀëΪ/ws_utc/begin.do£¬/ws_utc/config.do¡£
ws_utcΪWebLogic Web·þÎñ²âÊÔ¿Í»§¶Ë£¬ÆäÅäÖÃÒ³Ãæ´æÔÚδÊÚȨ½Ó¼ûµÄÎÊÌ⣬õ辶Ϊ/ws_utc/config.do¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷Õßͨ¹ý½Ó¼û´ËÅäÖÃÒ³Ãæ£¬Ïȸü¸Ä¹¤×÷Ŀ¼£¬ÓÃÓÐЧµÄWebLogic Webõè¾¶´úÌæ´æ´¢JKS KeystoresµÄÎļþĿ¼£¬¶øºóÔÚÉÏ´«JKS KeystoresʱÉÏ´«¶ñÒâµÄJSP¾ç±¾Îļþ¡£½Ó¼û×îÖÕµÄJSPÎļþõè¾¶µØÖ·£¬¼´¿É×öµ½´úÂëÖ´ÐУº

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷Õßͨ¹ýÀûÓô˷ì϶£¬¼´¿ÉÔÚÔ¶³ÌÇÒδ¾­ÊÚȨµÄÇé¿öÏÂÔÚWebLogic·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£


½¨¸´½¨Òé
1. ´Ë·ì϶ÐÔÖÊÊÇÎļþÉÏ´«£¬Ê¹ÓÃGA»Æ½ð¼×°²È«²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶²¹¶¡¼´¿É·ÀÓùwebshellÉÏ´«¡£

2. ʹÓÃOracle¹Ù·½°²È«²¼¶¡½øÐиüн¨¸´£ºhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html¡£


²Î¿¼Á´½Ó
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
https://mp.weixin.qq.com/s/y5JGmM-aNaHcs_6P9a-gRQ