WeblogicÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-01-15·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-2546£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-2551£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
CVE-2020-2546
WebLogic Server 10.3.6.0.0
WebLogic Server 12.1.3.0.0
CVE-2020-2551
Weblogic Server 10.3.6.0.0
Weblogic Server 12.1.3.0.0
Weblogic Server 12.2.1.3.0
Weblogic Server 12.2.1.4.0
·ì϶¸ÅÊö
WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÑë¼þ£¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀí´óÐÍÉ¢²¼Ê½ Web ÀûÓá¢ÍøÂçÀûÓúÍÊý¾Ý¿âÀûÓá£
CVE-2020-2546£º
¹¥»÷Õß¿ÉÄÜÀûÓÃWeblogic T3ºÍ̸½øÐз´ÐòÁл¯·ì϶µÄÀûÓôӶøÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£
CVE-2020-2551£º
¸Ã·ì϶Äܹ»ÈƹýOracle¹Ù·½ÔÚ2019Äê10Ô·ݰ䲼µÄ×îа²È«²¹¶¡¡£¹¥»÷ÕßÄܹ»Í¨¹ýIIOPºÍ̸Զ³Ì½Ó¼ûWeblogic Server·þÎñÆ÷ÉϵÄÔ¶³Ì½Ó¿Ú£¬´«Èë¶ñÒâÊý¾Ý£¬´Ó¶ø»ñÈ¡·þÎñÆ÷ȨÏÞ²¢ÔÚδÊÚȨÇé¿öÏÂÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Éý¼¶²¹¶¡£¬²Î¿¼oracle¹ÙÍø°ä²¼µÄ²¹¶¡¡£
»º½â´ëÊ©£º
CVE-2020-2546
ÈôÊDz»ÒÀÀµT3ºÍ̸½øÐÐJVMͨѶ£¬½ûÓÃT3ºÍ̸:
½øÈëWebLogic½ÚÔį̀£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬½øÈ밲ȫѡÏî¿¨Ò³Ãæ£¬µã»÷ɸѡÆ÷£¬ÅäÖÃɸѡÆ÷¡£ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨¿òÖÐÊäÈë 7001 deny t3 t3s ±£ÁôÉúЧ£¨Ðè³ÁÆô£©¡£
CVE-2020-2551
¿Éͨ¹ý¹Ø¹ØIIOPºÍ̸¶Ô´Ë·ì϶½øÐлº½â¡£²Ù×÷ÈçÏ£º
ÔÚWeblogic½ÚÔį̀ÖУ¬Ñ¡Ôñ¡°·þÎñ¡±->¡±AdminServer¡±->¡±ºÍ̸¡±£¬È¡µÞ¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡¡£²¢³ÁÆôWeblogicÏîÄ¿£¬Ê¹ÅäÖÃÉúЧ¡£
²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpujan2020.html


¾©¹«Íø°²±¸11010802024551ºÅ