¡¾Ô­´´Îó²î¡¿WebLogic Blind XXEÎó²î£¨CVE-2019-2647£©

Ðû²¼Ê±¼ä 2019-04-17
Îó²î±àºÅ£º CVE-2019-2647
Îó²îȪԴ£ºÍòÀû¹ú¼Ê¹ÙÍøADLab
Ðû²¼Ê±¼ä£º2019Äê4ÔÂ17ÈÕ

Îó²î¸ÅÊö


2019Äê4ÔÂ17ÈÕ£¬£¬£¬Oracle¹Ù·½Ðû²¼4Ô·ÝÇå¾²²¹¶¡, ²¹¶¡ÖаüÀ¨ÍòÀû¹ú¼Ê¹ÙÍøADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸øOracle¹Ù·½µÄWebLogic Blind XXEÎó²î£¬£¬£¬Îó²î±àºÅΪCVE-2019-2647¡£¡£¡£¡£¡£¡£Ê¹ÓøÃÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬£¬£¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£¡£¡£¡£


Îó²îʱ¼äÖá


2019Äê1ÔÂ9ÈÕ£º½«Îó²îÏêÇéÌá½»¸ø¹Ù·½£»£»£» £»£»£» £»£»
2019Äê1ÔÂ17ÈÕ£ºÈ·ÈÏÎó²î±£´æ²¢×îÏÈÐÞ¸´£»£»£» £»£»£» £»£»
2019Äê4ÔÂ17ÈÕ£ºOracle¹Ù·½Ðû²¼Çå¾²²¹¶¡¡£¡£¡£¡£¡£¡£

Ó°Ïì°æ±¾


WebLogic 10.3.6.0
WebLogic 12.1.3.0
WebLogic 12.2.1.2

WebLogic 12.2.1.3


Îó²îʹÓÃ


²âÊÔÇéÐΣºWebLogic Server 10.3.6.0£¨´ò²¹p28343311_1036_Generic£©


Îó²îʹÓÃЧ¹û£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

¹æ±Ü¼Æ»®


1¡¢Éý¼¶²¹¶¡


Oracle¹Ù·½¸üÐÂÁ´½ÓµØµã£ºhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html ¡£¡£¡£¡£¡£¡£


2¡¢¿ØÖÆT3ЭÒéµÄ»á¼û


WebLogic Blind XXEÎó²î±¬·¢ÓÚWebLogicµÄT3ЧÀÍ£¬£¬£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ЭÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶Ô¸ÃÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£µ±¿ª·ÅWebLogic¿ØÖÆÌ¨¶Ë¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê±£¬£¬£¬T3ЧÀÍ»áĬÈÏ¿ªÆô¡£¡£¡£¡£¡£¡£


Ïêϸ²Ù×÷£º


£¨1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£¡£¡£¡£


£¨2£©ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬£¬£¬0.0.0.0/0 * * deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£¡£¡£¡£


£¨3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£¡£¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾