WeblogicÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-15

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-2546£¬£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬ £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2551£¬£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬ £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CVE-2020-2546

WebLogic Server 10.3.6.0.0

WebLogic Server 12.1.3.0.0


CVE-2020-2551

Weblogic Server 10.3.6.0.0

Weblogic Server 12.1.3.0.0

Weblogic Server 12.2.1.3.0

Weblogic Server 12.2.1.4.0


Îó²î¸ÅÊö


WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÐļþ£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽ Web Ó¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦Óᣡ£¡£¡£


CVE-2020-2546£º

¹¥»÷ÕßÄܹ»Ê¹ÓÃWeblogic T3ЭÒé¾ÙÐз´ÐòÁл¯Îó²îµÄʹÓôӶøÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£


CVE-2020-2551£º

¸ÃÎó²î¿ÉÒÔÈÆ¹ýOracle¹Ù·½ÔÚ2019Äê10Ô·ÝÐû²¼µÄ×îÐÂÇå¾²²¹¶¡¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPЭÒéÔ¶³Ì»á¼ûWeblogic ServerЧÀÍÆ÷ÉϵÄÔ¶³Ì½Ó¿Ú£¬£¬ £¬£¬£¬£¬£¬´«Èë¶ñÒâÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø»ñȡЧÀÍÆ÷ȨÏÞ²¢ÔÚδÊÚȨÇéÐÎÏÂÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£


ÐÞ¸´½¨Òé


Éý¼¶²¹¶¡£¬£¬ £¬£¬£¬£¬£¬²Î¿¼oracle¹ÙÍøÐû²¼µÄ²¹¶¡¡£¡£¡£¡£


»º½â²½·¥£º


CVE-2020-2546


ÈôÊDz»ÒÀÀµT3ЭÒé¾ÙÐÐJVMͨѶ£¬£¬ £¬£¬£¬£¬£¬½ûÓÃT3ЭÒé:


½øÈëWebLogic¿ØÖÆÌ¨£¬£¬ £¬£¬£¬£¬£¬ÔÚbase_domainÉèÖÃÒ³ÃæÖУ¬£¬ £¬£¬£¬£¬£¬½øÈëÇ徲ѡÏî¿¨Ò³Ãæ£¬£¬ £¬£¬£¬£¬£¬µã»÷ɸѡÆ÷£¬£¬ £¬£¬£¬£¬£¬ÉèÖÃɸѡÆ÷¡£¡£¡£¡£ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬ £¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔò¿òÖÐÊäÈë 7001 deny t3 t3s ÉúÑÄÉúЧ£¨ÐèÖØÆô£©¡£¡£¡£¡£


CVE-2020-2551


¿Éͨ¹ý¹Ø±ÕIIOPЭÒé¶Ô´ËÎó²î¾ÙÐлº½â¡£¡£¡£¡£²Ù×÷ÈçÏ£º


ÔÚWeblogic¿ØÖÆÌ¨ÖУ¬£¬ £¬£¬£¬£¬£¬Ñ¡Ôñ¡°Ð§ÀÍ¡±->¡±AdminServer¡±->¡±Ð­Ò顱£¬£¬ £¬£¬£¬£¬£¬×÷·Ï¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡¡£¡£¡£¡£²¢ÖØÆôWeblogicÏîÄ¿£¬£¬ £¬£¬£¬£¬£¬Ê¹ÉèÖÃÉúЧ¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.oracle.com/security-alerts/cpujan2020.html