WeblogicÔÙ±¬¸ßΣÎó²î ÍòÀû¹ú¼Ê¹ÙÍøÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2019-10-17
2019Äê10ÔÂ15ÈÕ£¬ £¬£¬Oracle¹Ù·½Ðû²¼10Ô·ÝÇå¾²²¹¶¡, ÆäÖаüÀ¨ÁËÍòÀû¹ú¼Ê¹ÙÍøADLab·¢Ã÷²¢Ìá½»¸ø¹Ù·½µÄÁ½¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£



CVE-2019-2890 £¬ £¬£¬¹¥»÷Õß¿Éͨ¹ýT3ЭÒé¶Ô±£´æ¸ÃÎó²îµÄWebLogic×é¼þʵÑéÔ¶³Ìí§Òâ´úÂë¹¥»÷ £»£»£»£»


CVE-2019-2887£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýT3ЭÒé¶Ô±£´æ¸ÃÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÓ°Ïì°æ±¾



WebLogic Server 10.3.6.0
WebLogic Server 12.1.3.0
WebLogic Server 12.2.1.3



Îó²îʹÓÃ



Çå¾²Îó²î£ºCVE-2019-2890
²âÊÔÇéÐΣºWebLogic Server 10.3.6.0
Îó²îʹÓÃЧ¹û£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

Çå¾²Îó²î£ºCVE-2019-2887
²âÊÔÇéÐΣºWebLogic Server 10.3.6.0
Îó²îʹÓÃЧ¹û:  

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



½â¾ö¼Æ»®



? Éý¼¶¹Ù·½²¹¶¡
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

? ²úÆ·¼ì²âÓë·À»¤
ÒѰ²ÅÅÍòÀû¹ú¼Ê¹ÙÍøIDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æÔòÒѾ­Ï·¢²¢Ó¦Ó㬠£¬£¬¼´¿ÉÓÐÓüì²â»ò×è¶Ï¹¥»÷£º 


TCP_Oracle_WebLogic_·´ÐòÁл¯Îó²î[CVE-2019-2890] 
HTTP_WebLogic_XXE×¢ÈëÎó²î[CVE-2019-2887]

£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

£¨3£©ÌìÇåWebÓ¦ÓÃÇå¾²Íø¹Ø±¨¾¯½ØÍ¼£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Îó²îɨÃè


ÍòÀû¹ú¼Ê¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2019Äê10ÔÂ17ÈÕ½ôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬ £¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐмì²â£¬ £¬£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ·Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£¡£¡£


6070°æ±¾Éý¼¶°üΪ607000250£¬ £¬£¬Éý¼¶°üÏÂÔØµØµã£º
/article/type/1/146.html

ÇëÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ £¬£¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â£¬ £¬£¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£¡£¡£¡£¡£¡£¡£¡£

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾