Apache TomcatÎļþÔ̺¬·ì϶[CVE-2020-1938] GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2020-02-212ÔÂ20ÈÕ£¬¹ú¶ÈÐÅÏ¢°²È«·ì϶¹²ÏíÆ½Ì¨£¨CNVD£©°ä²¼¹ØÓÚApache TomcatµÄ°²È«²¼¸æ¡£Apache TomcatÎļþÔ̺¬·ì϶£¨CNVD-2020-10487£¬¶ÔÓ¦CVE-2020-1938£©¡£Tomcat AJPºÍ̸ÓÉÓÚ´æÔÚʵÏÖȱµãµ¼ÖÂÓйزÎÊý¿É¿Ø£¬¹¥»÷ÕßÀûÓø÷ì϶¿Éͨ¹ý»ú¹ØÌض¨²ÎÊý£¬¶ÁÈ¡·þÎñÆ÷webappϵÄËÁÒâÎļþ¡£Èô·þÎñÆ÷¶Ëͬʱ´æÔÚÎļþÉÏ´«Ö°ÄÜ£¬¹¥»÷Õ߿ɽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëµÄÖ´ÐС£
? ·ì϶ÀûÓãº
? ·ì϶ӰÏì°æ±¾£º
Tomcat 6.x
Tomcat 7.x<7.0.100
Tomcat 8.x<8.5.51
Tomcat 9.x<9.0.31
GA»Æ½ð¼×½â¾ö¹æ»®
Ò»¡¢ ½«Tomcatµ±¼´Éý¼¶µ½9.0.31¡¢8.5.51»ò7.0.100°æ±¾½øÐн¨¸´»ò½ûÓÃAJPºÍ̸¡£
¶þ¡¢ ²úÆ·¼ì²âÓë·À»¤£º
1¡¢ÒѲ¿ÊðGA»Æ½ð¼×IDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾÏ·¢²¢ÀûÓ㬼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£ºTCP_Tomcat_AJP13_ËÁÒâÎļþ¶ÁÈ¡[CVE-2020-1938]¡£
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
£¨3£©ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º
2¡¢·ì϶ɨÃè
GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2ÔÂ21ÈÕ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐмì²â£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ··ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£6070°æ±¾Éý¼¶°üΪ607000275£¬Éý¼¶°üÏÂÔØµØÖ·£º
/article/type/1/146.html
ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£


¾©¹«Íø°²±¸11010802024551ºÅ