Adobe ColdFusionÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-28·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-7839£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ColdFusion 2016 update 10ÒÔ¼°Ö®Ç°°æ±¾
ColdFusion 11 update 18ÒÔ¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
Adobe ColdFusionÊÇÃÀ¹ú°Â¶à±È£¨Adobe£©¹«Ë¾µÄÒ»Ì×¼±¾çÀûÓ÷¨Ê½¿ª·¢Æ½Ì¨¡£¸Ãƽ̨Ô̺¬¼¯³É¿ª·¢»·¾³ºÍ¾ç±¾Ëµ»°¡£
ColdfusionÈí¼þÖдæÔÚÁ½¸öÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶£¬¾ßÌåÈçÏ£º
CVE-2019-7838
¸Ã·ì϶ΪÎļþÀ©´óÃûºÚÃûµ¥Èƹý·ì϶£¬µ±ÎļþÉÏÔØÄ¿Â¼¿Éͨ¹ýWeb½Ó¼ûʱ£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶½øÐжñÒâ¹¥»÷£¬Ö´ÐÐËÁÒâ´úÂë¡£
CVE-2019-7839
JNBridgeÊÇÒ»ÖÖ¼¯³ÉJavaºÍ.NETÀûÓ÷¨Ê½´úÂëµÄ¼¼Êõ¡£¸Ã¼¼Êõͨ¹ýÉè¼ÆÔÊÐí²»ÊÜÏ޶ȽӼûÔ¶³ÌJavaÔËÐÐʱµÄ»·¾³£¬´Ó¶øÔÊÐíÖ´ÐÐËÁÒâ´úÂëºÍϵͳºÅÁî¡£
ÔÚWindowsÉÏÔËÐеÄColdfusion·þÎñÆ÷¹«¿ªJNBridge TCP¶Ë¿Ú6093»ò6095ÉϵÄÍøÂçÕìÌýÆ÷¡£¿ÉÄܽӼû¸Ã·þÎñµÄ¹¥»÷ÕßÄܹ»Ö´ÐÐËÁÒâ²Ù×÷Java´úÂë»òϵͳºÅÁĬÈÏÇé¿öÏ£¬´Ë·þÎñÒÔ×î¸ßȨÏÞ£¨SYSTEM£©ÔËÐС£¹¥»÷ÕßÄܹ»Í¨¹ýJNBridge¼¼Êõ²»ÊÜÏ޶ȵؽӼûÔ¶³ÌJavaÔËÐÐʱ»·¾³£¬´Ó¶øÔÊÐíÖ´ÐÐËÁÒâ´úÂëºÍϵͳºÅÁî¡£
·ì϶ÑéÖ¤
CVE-2019-7838
ÔÝÎÞPOC/EXP
CVE-2019-7839
EXP:https://cxsecurity.com/issue/WLB-2019060172
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://helpx.adobe.com/security/products/coldfusion/apsb19-27.html
²Î¿¼Á´½Ó
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201906-514


¾©¹«Íø°²±¸11010802024551ºÅ