WebLogic í§ÒâÎļþÉÏ´«Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-19
Îó²î±àºÅºÍ¼¶±ð

CVE-2018-2894  ³§ÉÌ×ÔÆÀ£º9.8  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
WebLogic 10.3.6.0
WebLogic 12.1.3.0
WebLogic 12.2.1.2

WebLogic 12.2.1.3


Îó²î¸ÅÊö
Oracle¹Ù·½Ðû²¼ÁË7Ô·ݵÄÒªº¦²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬£¬£¬£¬£¬£¬ÆäÖÐÕë¶Ô¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐеĸßΣÎó²î CVE-2018-2894 ¾ÙÐÐÐÞ¸´£ºhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html¡£¡£¡£¡£¡£¡£¡£
½ñÌì7ÔÂ19ºÅ¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄCNCERT·¢³öͨ¸æ£¬£¬£¬£¬£¬£¬Ö¸³öCVE-2018-2894ʵÖÊÉÏΪí§ÒâÎļþÉÏ´«Îó²î£ºhttps://mp.weixin.qq.com/s/y5JGmM-aNaHcs_6P9a-gRQ¡£¡£¡£¡£¡£¡£¡£
WebLogicÖÎÀí¶ËδÊÚȨµÄÁ½¸öÒ³Ãæ±£´æí§ÒâÉÏ´«getshellÎó²î£¬£¬£¬£¬£¬£¬¿ÉÖ±½Ó»ñȡȨÏÞ¡£¡£¡£¡£¡£¡£¡£Á½¸öÒ³Ãæ»®·ÖΪ/ws_utc/begin.do£¬£¬£¬£¬£¬£¬/ws_utc/config.do¡£¡£¡£¡£¡£¡£¡£
ws_utcΪWebLogic WebЧÀͲâÊÔ¿Í»§¶Ë£¬£¬£¬£¬£¬£¬ÆäÉèÖÃÒ³Ãæ±£´æÎ´ÊÚȨ»á¼ûµÄÎÊÌ⣬£¬£¬£¬£¬£¬Â·¾¶Îª/ws_utc/config.do¡£¡£¡£¡£¡£¡£¡£

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


¹¥»÷Õßͨ¹ý»á¼û´ËÉèÖÃÒ³Ãæ£¬£¬£¬£¬£¬£¬Ïȸü¸ÄÊÂÇéĿ¼£¬£¬£¬£¬£¬£¬ÓÃÓÐÓõÄWebLogic Web·¾¶Ìæ»»´æ´¢JKS KeystoresµÄÎļþĿ¼£¬£¬£¬£¬£¬£¬È»ºóÔÚÉÏ´«JKS KeystoresʱÉÏ´«¶ñÒâµÄJSP¾ç±¾Îļþ¡£¡£¡£¡£¡£¡£¡£»á¼û×îÖÕµÄJSPÎļþ·¾¶µØµã£¬£¬£¬£¬£¬£¬¼´¿É×öµ½´úÂëÖ´ÐУº

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


¹¥»÷Õßͨ¹ýʹÓôËÎó²î£¬£¬£¬£¬£¬£¬¼´¿ÉÔÚÔ¶³ÌÇÒδ¾­ÊÚȨµÄÇéÐÎÏÂÔÚWebLogicЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé
1. ´ËÎó²îʵÖÊÊÇÎļþÉÏ´«£¬£¬£¬£¬£¬£¬Ê¹ÓÃÍòÀû¹ú¼Ê¹ÙÍøÇå¾²²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶²¹¶¡¼´¿É·ÀÓùwebshellÉÏ´«¡£¡£¡£¡£¡£¡£¡£

2. ʹÓÃOracle¹Ù·½Çå¾²²¼¶¡¾ÙÐиüÐÂÐÞ¸´£ºhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
https://mp.weixin.qq.com/s/y5JGmM-aNaHcs_6P9a-gRQ