WebLogic¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-16

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-2891 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


WebLogic 10.3.6.0.0

WebLogic 12.1.3.0.0

WebLogic 12.2.1.3.0


·ì϶¸ÅÊö


WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÑë¼þ £¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀí´óÐÍÉ¢²¼Ê½ Web ÀûÓá¢ÍøÂçÀûÓúÍÊý¾Ý¿âÀûÓá£


Oracle¹Ù·½°ä²¼ÁË2019Äê10ÔµÄÑϳÁ²¹¶¡¸üÐÂCPU£¨Critical Patch Update£© £¬ÆäÖн¨¸´ÁËWebLogic ´æÔÚÓÚConsole×é¼þÖеÄÒ»¸ö¸ßΣ·ì϶£¨CVE-2019-2891£©¡£



¹¥»÷ÕßÔÚδÊÚȨµÄÇé¿öÏ £¬Äܹ»Í¨¹ý·¢ËÍHTTPÒªÇó¹¥»÷WebLogic Server¡£Ò»µ©ÀûÓóɹ¦ £¬±ã¿ÉÊÕÊÜÖ¸±êµÄWebLogic Server¡£


¸Ã·ì϶ÀûÓÃÄѶȽϸß¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html¡£


²Î¿¼Á´½Ó


https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

https://www.oracle.com/technetwork/security-advisory/cpuoct2019verbose-5072833.html