Adobe ColdFusionÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-28

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7838£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2019-7839£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ColdFusion 2018 update 3ÒÔ¼°Ö®Ç°°æ±¾
ColdFusion 2016 update 10ÒÔ¼°Ö®Ç°°æ±¾

ColdFusion 11 update 18ÒÔ¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


Adobe ColdFusionÊÇÃÀ¹ú°Â¶à±È£¨Adobe£©¹«Ë¾µÄÒ»Ì׿ìËÙÓ¦ÓóÌÐò¿ª·¢Æ½Ì¨¡£¡£¡£¸Ãƽ̨°üÀ¨¼¯³É¿ª·¢ÇéÐκ;籾ÓïÑÔ¡£¡£¡£ 


ColdfusionÈí¼þÖб£´æÁ½¸öÑÏÖØÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬ÏêϸÈçÏ£º


CVE-2019-7838


¸ÃÎó²îΪÎļþÀ©Õ¹ÃûºÚÃûµ¥ÈƹýÎó²î£¬£¬£¬£¬£¬£¬µ±ÎļþÉÏÔØÄ¿Â¼¿Éͨ¹ýWeb»á¼ûʱ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²î¾ÙÐжñÒâ¹¥»÷£¬£¬£¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£


CVE-2019-7839


JNBridgeÊÇÒ»ÖÖ¼¯³ÉJavaºÍ.NETÓ¦ÓóÌÐò´úÂëµÄÊÖÒÕ¡£¡£¡£¸ÃÊÖÒÕͨ¹ýÉè¼ÆÔÊÐí²»ÊÜÏÞÖÆ»á¼ûÔ¶³ÌJavaÔËÐÐʱµÄÇéÐΣ¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÖ´ÐÐí§Òâ´úÂëºÍϵͳÏÂÁî¡£¡£¡£


ÔÚWindowsÉÏÔËÐеÄColdfusionЧÀÍÆ÷¹ûÕæJNBridge TCP¶Ë¿Ú6093»ò6095ÉϵÄÍøÂçÕìÌýÆ÷¡£¡£¡£Äܹ»»á¼û¸ÃЧÀ͵Ĺ¥»÷Õß¿ÉÒÔÖ´ÐÐí§Òâ²Ù×÷Java´úÂë»òϵͳÏÂÁî¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬£¬£¬´ËЧÀÍÒÔ×î¸ßȨÏÞ£¨SYSTEM£©ÔËÐС£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýJNBridgeÊÖÒÕ²»ÊÜÏÞÖÆµØ»á¼ûÔ¶³ÌJavaÔËÐÐʱÇéÐΣ¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÖ´ÐÐí§Òâ´úÂëºÍϵͳÏÂÁî¡£¡£¡£


Îó²îÑéÖ¤


CVE-2019-7838


ÔÝÎÞPOC/EXP


CVE-2019-7839


EXP:https://cxsecurity.com/issue/WLB-2019060172


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://helpx.adobe.com/security/products/coldfusion/apsb19-27.html


²Î¿¼Á´½Ó


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201906-520
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201906-514