Oracle¶à¸ö²úÆ·°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-150x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
WebLogic |
CVE-2020-14625 |
|
ÑϳÁ |
ÊÇ |
WebLogic 12.2.1.3.0 WebLogic 12.2.1.4.0 WebLogic 14.1.1.0.0 |
|
CVE-2020-14644 |
|
ÑϳÁ |
ÊÇ |
||
|
CVE-2020-14687 |
|
ÑϳÁ |
ÊÇ |
||
|
CVE-2020-14645 |
|
ÑϳÁ |
ÊÇ |
WebLogic 10.3.6.0.0 WebLogic 12.1.3.0.0 WebLogic 12.2.1.3.0 WebLogic 12.2.1.4.0 WebLogic 14.1.1.0.0 |
|
|
Oracle SD-WAN Aware |
CVE-2020-14701 |
|
ÑϳÁ |
ÊÇ |
Oracle SD-WAN Aware 8.2 |
|
Oracle SD-WAN Edge |
CVE-2020-14606 |
|
ÑϳÁ |
ÊÇ |
Oracle SD-WAN Edge 8.2,9.0 |
0x01 ·ì϶ÏêÇé
2020Äê7ÔÂ14ÈÕ£¬Oracle¹Ù·½°ä²¼°²È«²¼¸æ£¬½¨¸´ÁË433¸ö°²È«·ì϶£¬Éæ¼°ÁËOracle Weblogic¡¢Oracle CoherenceµÈ¶à¿î²úÆ·¡£ÆäÖÐÔ̺¬ËĸöÆÀ·ÖΪ9.8µÄOracle WebLogic Server·´ÐòÁл¯·ì϶£¨CVE-2020-14625¡¢CVE-2020-14644¡¢CVE-2020-14645 ¡¢CVE-2020-14687£©£¬Á½¸öÆÀ·ÖΪ10µÄOracle Communications Applications°²È«·ì϶£¨CVE-2020-14701¡¢CVE-2020-14606£©¡£
Oracle WebLogic Server·´ÐòÁл¯·ì϶
ÕâËĸö·ì϶µ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýIIOP¡¢T3ºÍ̸·¢ËͶñÒâÒªÇ󣬴ӶøÔÚOracle WebLogic ServerÖ´ÐжñÒâ´úÂë¡£
Oracle Communications Applications°²È«·ì϶
ÕâÁ½¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼²¹¶¡£¬ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpujul2020.html
Weblogicһʱ½¨²¹½¨Ò飺
1. ÈôÊDz»ÒÀÀµT3ºÍ̸½øÐÐJVMͨѶ£¬½ûÓÃT3ºÍ̸¡£
? ½øÈëWebLogic½ÚÔį̀£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬½øÈ밲ȫѡÏî¿¨Ò³Ãæ£¬µã»÷ɸѡÆ÷£¬ÅäÖÃɸѡÆ÷£»
? ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨¿òÖÐÊäÈë 7001 deny t3 t3s±£ÁôÉúЧ£»
? ³ÁÆôWeblogicÏîÄ¿£¬Ê¹ÅäÖÃÉúЧ¡£
2. ÈôÊDz»ÒÀÀµIIOPºÍ̸½øÐÐJVMͨѶ£¬½ûÓÃIIOPºÍ̸¡£
? ½øÈëWebLogic½ÚÔį̀£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬½øÈ밲ȫѡÏî¿¨Ò³Ãæ£»
? Ñ¡Ôñ¡°·þÎñ¡±->¡±AdminServer¡±->¡±ºÍ̸¡±£¬È¡µÞ¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡£»
? ³ÁÆôWeblogicÏîÄ¿£¬Ê¹ÅäÖÃÉúЧ¡£
0x03 ÓйØÐÂÎÅ
0x04 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpujul2020.html
0x05 ¹¦·òÏß
2020-07-14 Oracle¹Ù·½°ä²¼°²È«²¼¸æ
2020-07-15 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ