WeblogicÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-15

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-2546£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-2551£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CVE-2020-2546

WebLogic Server 10.3.6.0.0

WebLogic Server 12.1.3.0.0


CVE-2020-2551

Weblogic Server 10.3.6.0.0

Weblogic Server 12.1.3.0.0

Weblogic Server 12.2.1.3.0

Weblogic Server 12.2.1.4.0


·ì϶¸ÅÊö


WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÑë¼þ£¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀí´óÐÍÉ¢²¼Ê½ Web ÀûÓá¢ÍøÂçÀûÓúÍÊý¾Ý¿âÀûÓá£


CVE-2020-2546£º

¹¥»÷Õß¿ÉÄÜÀûÓÃWeblogic T3ºÍ̸½øÐз´ÐòÁл¯·ì϶µÄÀûÓôӶøÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£


CVE-2020-2551£º

¸Ã·ì϶Äܹ»ÈƹýOracle¹Ù·½ÔÚ2019Äê10Ô·ݰ䲼µÄ×îа²È«²¹¶¡¡£¹¥»÷ÕßÄܹ»Í¨¹ýIIOPºÍ̸Զ³Ì½Ó¼ûWeblogic Server·þÎñÆ÷ÉϵÄÔ¶³Ì½Ó¿Ú£¬´«Èë¶ñÒâÊý¾Ý£¬´Ó¶ø»ñÈ¡·þÎñÆ÷ȨÏÞ²¢ÔÚδÊÚȨÇé¿öÏÂÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Éý¼¶²¹¶¡£¬²Î¿¼oracle¹ÙÍø°ä²¼µÄ²¹¶¡¡£


»º½â´ëÊ©£º


CVE-2020-2546


ÈôÊDz»ÒÀÀµT3ºÍ̸½øÐÐJVMͨѶ£¬½ûÓÃT3ºÍ̸:


½øÈëWebLogic½ÚÔį̀£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬½øÈ밲ȫѡÏî¿¨Ò³Ãæ£¬µã»÷ɸѡÆ÷£¬ÅäÖÃɸѡÆ÷¡£ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨¿òÖÐÊäÈë 7001 deny t3 t3s ±£ÁôÉúЧ£¨Ðè³ÁÆô£©¡£


CVE-2020-2551


¿Éͨ¹ý¹Ø¹ØIIOPºÍ̸¶Ô´Ë·ì϶½øÐлº½â¡£²Ù×÷ÈçÏ£º


ÔÚWeblogic½ÚÔį̀ÖУ¬Ñ¡Ôñ¡°·þÎñ¡±->¡±AdminServer¡±->¡±ºÍ̸¡±£¬È¡µÞ¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡¡£²¢³ÁÆôWeblogicÏîÄ¿£¬Ê¹ÅäÖÃÉúЧ¡£


²Î¿¼Á´½Ó


https://www.oracle.com/security-alerts/cpujan2020.html