WebLogic CVE-2018-2628·´ÐòÁл¯·ì϶¸´ÏÖ
°ä²¼¹¦·ò 2018-04-18Ò»¡¢·ìϼûèÊö
2018Äê4ÔÂ18ÈÕÁ賿£¬Oracle¹Ù·½°ä²¼ÁË4Ô·ݵݲȫ²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬¸üÐÂÖн¨¸´ÁËÒ»¸ö¸ßΣWebLogic·´ÐòÁл¯·ì϶CVE-2018-2628£¨CNVD-2018-07811¡¢CNNVD-201804-803£©¡£¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷£¬²¢¿É»ñȡָ±êϵͳËùÓÐȨÏÞ¡£
Oracle¹Ù·½°ä²¼µÄ·ì϶ÐÅÏ¢ÈçÏÂͼËùʾ£º
¶þ¡¢·ì϶ÑéÖ¤
GA»Æ½ð¼×ADLabµÚÒ»¹¦·ò¶ÔCVE-2018-2628½øÐÐÁ˸ú×Ù·ÖÎö£¬²¢³É¹¦¸´ÏÖÁ˸÷ì϶¡£¸´ÏÖÁ˾ÖÈçÏÂËùʾ£º
Èý¡¢·ì϶ӰÏì
¸Ã·ì϶ӰÏìWebLogic 10.3.6.0¡¢WebLogic 12.1.3.0¡¢WebLogic 12.2.1.2¡¢WebLogic 12.2.1.3¶à¸ö°æ±¾¡£Ä¿Ç°ÒѾ·¢ÏÖÕë¶Ô¸Ã·ì϶µÄÀûÓò½Ö裬ÀûÓò½Öè½ÏΪµ¥Ò»£¬·çÏսϴó£¬ÓйØÓû§¼°³§ÉÌÓ¦ÒýÆðÆ÷³Á¡£
ËÄ¡¢·ì϶½¨¸´
Oracle¹Ù·½ÒѰ䲼Õë¶Ô¸Ã·ì϶µÄ²¹¶¡£¬¿É¸üйٷ½×îеIJ¹¶¡¡£Oracle¹Ù·½²¹¶¡±ØÒªÓû§³ÖÓÐÕý°æÈí¼þµÄÐí¿ÉÕʺţ¬Ê¹ÓÃÐí¿ÉÕʺŵǽ https://support.oracle.com ºó£¬Äܹ»ÏÂÔØ×îв¹¶¡¡£
¼¸µã½¨Ò飺
1¡¢Éý¼¶JDK°æ±¾¡£ÓÉÓÚJavaÔÚ½ñÄêÒ»Ô·ÝÒÔÀ´¸üÐÂÁË·´ÐòÁл¯·ÀÓù½Ó¿Ú£¬Äܹ»»º½â·´ÐòÁл¯·ì϶µÄÓ°Ïì¡£
2¡¢Éý¼¶WebLogic¡¢É¾³ý²»±ØÒªµÄÒ³Ãæ£¬ËãÕʲ»°²È«µÄµÚÈý·½¿â¡£
3¡¢½ûÓÃT3ºÍ̸¡£
·ì϶Á´½Ó£º
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html


¾©¹«Íø°²±¸11010802024551ºÅ