¡¾·ì϶¹«¸æ¡¿Oracle WebLogic Server δÊÚȨ½Ó¼û·ì϶(CVE-2025-30762)
°ä²¼¹¦·ò 2025-07-16Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Oracle WebLogic Server δÊÚȨ½Ó¼û·ì϶ | ||
CVE ID | CVE-2025-30762 | ||
·ì϶ÀàÐÍ | δÊÚȨ½Ó¼û | ·¢ÏÖ¹¦·ò | 2025-07-16 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Oracle WebLogic ServerÊÇOracle¹«Ë¾ÍƳöµÄÒ»¿îÆóÒµ¼¶ÀûÓ÷þÎñÆ÷£¬ÖØÒªÓÃÓÚ¹¹½¨¡¢²¿ÊðºÍÔËÐÐJava EE£¨ÆóÒµ¼¶JavaÀûÓ÷¨Ê½£©¡£ËüÖ§³ÖWeb·þÎñ¡¢É¢²¼Ê½ÏµÍ³¡¢ÊÂÎñÖÎÀí¡¢ÓÆ¾ÃÐÔ¡¢ÐÂÎÅ´«µÝµÈÖ°ÄÜ£¬¿í·ºÀûÓÃÓÚÆóÒµ¼¶ÀûÓúÍÔÆÍÆËã»·¾³¡£×÷Ϊһ¸öÖÐÑë¼þƽ̨£¬WebLogicÌṩ¸ß¿ÉÓÃÐÔ¡¢¿ÉÉìËõÐԺͰ²È«ÐÔ£¬ºÏÓÃÓÚ¹¹½¨´ó¹æÄ£¡¢ÈÝ´íµÄÆóÒµÀûÓá£
2025Äê7ÔÂ16ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Oracle WebLogic Server²úÆ·ÖеÄÒ»¸öδÊÚȨ½Ó¼û·ì϶¡£¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤£¬½öͨ¹ýT3»òIIOPºÍ̸½øÐÐÍøÂç½Ó¼û£¬±ã¿É¹¥»÷Oracle WebLogic Server¡£³É¹¦ÀûÓô˷ì϶ºó£¬¹¥»÷Õß¿ÉÄÜδ¾ÊÚȨ½Ó¼ûWebLogic ServerÖÐËùÓпɽӼûµÄ¹Ø¼üÊý¾Ý¡£·ì϶ÆÀ·Ö7.5·Ö£¬·ì϶¼¶±ð¸ßΣ¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://www.oracle.com/security-alerts/cpujul2025.html
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


¾©¹«Íø°²±¸11010802024551ºÅ