WebLogic¸ßΣ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-10-16·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-2891£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
WebLogic 10.3.6.0.0
WebLogic 12.1.3.0.0
WebLogic 12.2.1.3.0
·ì϶¸ÅÊö
WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÑë¼þ£¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀí´óÐÍÉ¢²¼Ê½ Web ÀûÓá¢ÍøÂçÀûÓúÍÊý¾Ý¿âÀûÓá£
Oracle¹Ù·½°ä²¼ÁË2019Äê10ÔµÄÑϳÁ²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬ÆäÖн¨¸´ÁËWebLogic ´æÔÚÓÚConsole×é¼þÖеÄÒ»¸ö¸ßΣ·ì϶£¨CVE-2019-2891£©¡£
¹¥»÷ÕßÔÚδÊÚȨµÄÇé¿öÏ£¬Äܹ»Í¨¹ý·¢ËÍHTTPÒªÇó¹¥»÷WebLogic Server¡£Ò»µ©ÀûÓóɹ¦£¬±ã¿ÉÊÕÊÜÖ¸±êµÄWebLogic Server¡£
¸Ã·ì϶ÀûÓÃÄѶȽϸߡ£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html¡£
²Î¿¼Á´½Ó
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019verbose-5072833.html


¾©¹«Íø°²±¸11010802024551ºÅ