WeblogicÔÙ±¬¸ßΣ·ì϶ GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2019-10-17
CVE-2019-2890 £¬¹¥»÷Õß¿Éͨ¹ýT3ºÍ̸¶Ô´æÔڸ÷ì϶µÄWebLogic×é¼þÖ´ÐÐÔ¶³ÌËÁÒâ´úÂë¹¥»÷£»
·ì϶ӰÏì°æ±¾
WebLogic Server 12.1.3.0
WebLogic Server 12.2.1.3
·ì϶ÀûÓÃ
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ£º

°²È«·ì϶£ºCVE-2019-2887
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ:

https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
? ²úÆ·¼ì²âÓë·À»¤
ÒѲ¿ÊðGA»Æ½ð¼×IDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾÏ·¢²¢ÀûÓ㬼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£º
TCP_Oracle_WebLogic_·´ÐòÁл¯·ì϶[CVE-2019-2890]
HTTP_WebLogic_XXE×¢Èë·ì϶[CVE-2019-2887]
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º

£¨3£©ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º
·ì϶ɨÃè
GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2019Äê10ÔÂ17ÈÕ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐмì²â£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ··ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£
/article/type/1/146.html
ÇëÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£



¾©¹«Íø°²±¸11010802024551ºÅ