2020-10-20
°ä²¼¹¦·ò 2020-10-21ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_MidaSolutionseFramework_ajaxreq.phpºÅÁî×¢Èë·ì϶ [CVE-2020-15920][CNNVD-202007-1517] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Mida SolutionsÊÇÒ»¼ÒרһÓÚͳһͨѶ(UC)µÄ¸ß¼¼ÊõÒâ´óÀû¹«Ë¾,MidaÍŶÓÒѳÉΪͳһºÏ×÷ºÍרҵ¹µÍ¨µÄÈ«Çò¸¨µ¼Õß,ÏÕЩËùÓÐÐÐÒµµÄ·þÎñÌṩÉÌ£¬ÏµÍ³¼¯³ÉÉÌ¡£ÆäºÏ×÷ͬ°éÓÐ΢Èí,˼¿Æ,»ÝÆÕ,ÖйúµçÐŵÈ40¸öÊÀ½ç³ÛÃûÆóÒµ¡£Mida eFrameworkÊÇMida Solutions¹«Ë¾ÆìÏÂÊÓÆµºÍÓïÒôÀûÓ÷¨Ê½µÄÆëÈ«·þÎñÌ×¼þ£¬ÓëÏÕЩËùÓÐÖØÒªµÄUCƽ̨¼æÈÝ¡£¸ÃÌ×¼þÔ̺¬»°ÎñÔ±½ÚÔį̀£¬¼Í¼Æ÷£¬´«Õæ·þÎñÆ÷£¬¼Æ·Ñ£¬¶ÓÁÐÖÎÀíÆ÷£¬×Ô¶¯»°ÎñÔ±£¬Òƶ¯ÀûÓ÷¨Ê½£¬µç»°·þÎñ¡£ |
¸üй¦·ò£º | 20201020 |
ÊÂÎñÃû³Æ£º | TCP_Java·´ÐòÁл¯_MozillaRhino1_ÀûÓÃÁ´¹¥»÷ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃMozillaRhino1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ. rhinoÊÇʹÓÃjava´úÂëʵÏÖµÄjavascriptÚ¹ÊÍÆ÷£¬ËüʵÏÖÁËjavascriptµÄÖ÷Ì⣬ÇкÏEcma-262³ß¶È£¬Ö§³Öjavascript³ß¶ÈµÄËùÓиöÐÔ¡£ |
¸üй¦·ò£º | 20201020 |
ÊÂÎñÃû³Æ£º | HTTP_JBossMQ_JMS_·´ÐòÁл¯·ì϶[CVE-2017-7504][CNNVD-201705-937] |
°²È«ÀàÐÍ£º | ÍøÂçͨѶ |
ÊÂÎñÃèÊö£º | Red Hat JBoss Application Server ÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´ÀûÓ÷þÎñÆ÷¡£JBoss AS 4.x¼°Ö®Ç°°æ±¾ÖУ¬JbossMQʵÏÖ¹ý³ÌµÄJMS over HTTP Invocation LayerµÄHTTPServerILServlet.javaÎļþ´æÔÚ·´ÐòÁл¯·ì϶£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÔìµÄÐòÁл¯Êý¾ÝÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20201020 |
ÊÂÎñÃû³Æ£º | TCP_ͨÓÃ_JavaRMI·´ÐòÁл¯_Ô¶³ÌºÅÁîÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃJavaRMI·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶½øÐй¥»÷µÄÐÐΪ£¬JavaRMI·´ÐòÁл¯Ô¶³ÌºÅÁîÖ´Ðзì϶½øÐй¥»÷µÄÐÐΪÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20201020 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_RDPÔ¶³Ì×ÀÃæµÇ¼_»á»°ÏÎ½Ó |
°²È«ÀàÐÍ£º | °²È«Éó¼Æ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·Ö÷»úÔÚÏòÖ÷ÕÅIPµØÖ·Ö÷»úÔ¶³Ì×ÀÃæµÇ¼¿ÚÁî²Â½âµÄÐÐΪ¡£ Ô¶³Ì×ÀÃæÏνÓ×é¼þÊÇ´ÓWindows 2000 ServerÆðÍ·ÓÉ΢Èí¹«Ë¾ÌṩµÄ£¬ÔÚWINDOWS 2000 SERVERÖÐËû²»ÊÇĬÈÏ×°Öõġ£¸Ã×é¼þÒÑ¾ÍÆ³öÊܵ½Á˺öàÓû§µÄÓµ´÷ºÍ°®ºÃ£¬ËùÒÔÔÚWINDOWS WINDOWS2003¿ªÆô²½ÖèºÍXPÀàËÆ£¬Í¬Ñù¶Ô²Ù×÷²½Öè½øÐÐÁ˼ò»¯¡£²½ÖèÈçÏ£º µÚÒ»²½£ºÔÚ×ÀÃæ¡°ÎҵĵçÄÔ¡±ÉϵãÊó±êÓÒ¼ü£¬Ñ¡Ôñ¡°ÊôÐÔ¡±¡£XPºÍ2003ÖÐ΢Èí¹«Ë¾½«¸Ã×é¼þµÄÆôÓò½Öè½øÐÐÁ˶¦Ð£¬ÎÒÃÇͨ¹ýµ¥Ò»µÄ¹´Ñ¡¾ÍÄܹ»ÊµÏÖÔÚXPºÍ2003ÏÂÔ¶³Ì×ÀÃæÏνÓÖ°ÄܵĿªÆô¡£ÈôÊÇÖ¸±êÖ÷»ú¿ªÆôÁËÔ¶³ÌÖÕ¶Ë·þÎñ£¬Ä¬È϶˿ÚÊÇ3389£¬¹¥»÷Õßͨ¹ýÂŴγ¢ÊÔÓû§ÃûºÍÃÜÂëµÄ·½Ê½À´²Â½âÓû§¿ÚÁÈôÊDZ»²ÂÖй¥»÷Õß¾ÍÄܹ»»ñÇе±Ç°Óû§µÄËùÓÐȨÏÞ£¬½ø¶øÓÐÓпÉÄÜ»ñµÃÖÎÀíԱȨÏÞ¡£ µÚ¶þ²½£ºÔÚµ¯³öµÄϵͳÊôÐÔ´°¿Úµ±Ñ¡Ôñ¡°Ô¶³Ì¡±±êÇ©¡£ µÚÈý²½£ºÔÚÔ¶³Ì±êÇ©ÖÐÕÒµ½¡°Ô¶³Ì×ÀÃæ¡±£¬ÔÚ¡°´ðÀíÓû§Ïνӵ½ÕâÌ¨ÍÆËã»ú¡±Ç°¶Ô¹´È¥µôºóÈ·¶¨¼´¿ÉʵÏÖÔ¶³Ì×ÀÃæÏνÓÖ°ÄܵĹعء£ |
¸üй¦·ò£º | 20201020 |
ÊÂÎñÃû³Æ£º | TCP_Oracle_WebLogic_·´ÐòÁл¯·ì϶[CVE-2016-3510] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracle WebLogic·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£ |
¸üй¦·ò£º | 20201013 |


¾©¹«Íø°²±¸11010802024551ºÅ