Oracle¶à¸ö²úÆ·Çå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-07-150x00 Îó²î¸ÅÊö
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
WebLogic |
CVE-2020-14625 |
|
ÑÏÖØ |
ÊÇ |
WebLogic 12.2.1.3.0 WebLogic 12.2.1.4.0 WebLogic 14.1.1.0.0 |
CVE-2020-14644 |
|
ÑÏÖØ |
ÊÇ |
||
CVE-2020-14687 |
|
ÑÏÖØ |
ÊÇ |
||
CVE-2020-14645 |
|
ÑÏÖØ |
ÊÇ |
WebLogic 10.3.6.0.0 WebLogic 12.1.3.0.0 WebLogic 12.2.1.3.0 WebLogic 12.2.1.4.0 WebLogic 14.1.1.0.0 |
|
Oracle SD-WAN Aware |
CVE-2020-14701 |
|
ÑÏÖØ |
ÊÇ |
Oracle SD-WAN Aware 8.2 |
Oracle SD-WAN Edge |
CVE-2020-14606 |
|
ÑÏÖØ |
ÊÇ |
Oracle SD-WAN Edge 8.2,9.0 |
0x01 Îó²îÏêÇé
2020Äê7ÔÂ14ÈÕ£¬£¬£¬£¬£¬Oracle¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁË433¸öÇå¾²Îó²î£¬£¬£¬£¬£¬Éæ¼°ÁËOracle Weblogic¡¢Oracle CoherenceµÈ¶à¿î²úÆ·¡£¡£¡£¡£¡£ÆäÖаüÀ¨ËĸöÆÀ·ÖΪ9.8µÄOracle WebLogic Server·´ÐòÁл¯Îó²î£¨CVE-2020-14625¡¢CVE-2020-14644¡¢CVE-2020-14645 ¡¢CVE-2020-14687£©£¬£¬£¬£¬£¬Á½¸öÆÀ·ÖΪ10µÄOracle Communications ApplicationsÇå¾²Îó²î£¨CVE-2020-14701¡¢CVE-2020-14606£©¡£¡£¡£¡£¡£
Oracle WebLogic Server·´ÐòÁл¯Îó²î
ÕâËĸöÎó²îµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýIIOP¡¢T3ÐÒé·¢ËͶñÒâÇëÇ󣬣¬£¬£¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£
Oracle Communications ApplicationsÇå¾²Îó²î
ÕâÁ½¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpujul2020.html
WeblogicÔÝʱÐÞ²¹½¨Ò飺
1. ÈôÊDz»ÒÀÀµT3ÐÒé¾ÙÐÐJVMͨѶ£¬£¬£¬£¬£¬½ûÓÃT3ÐÒé¡£¡£¡£¡£¡£
? ½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÔÚbase_domainÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈëÇ徲ѡÏî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷ɸѡÆ÷£¬£¬£¬£¬£¬ÉèÖÃɸѡÆ÷£»£»£»£»£»£»
? ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔò¿òÖÐÊäÈë 7001 deny t3 t3sÉúÑÄÉúЧ£»£»£»£»£»£»
? ÖØÆôWeblogicÏîÄ¿£¬£¬£¬£¬£¬Ê¹ÉèÖÃÉúЧ¡£¡£¡£¡£¡£
2. ÈôÊDz»ÒÀÀµIIOPÐÒé¾ÙÐÐJVMͨѶ£¬£¬£¬£¬£¬½ûÓÃIIOPÐÒé¡£¡£¡£¡£¡£
? ½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÔÚbase_domainÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈëÇ徲ѡÏî¿¨Ò³Ãæ£»£»£»£»£»£»
? Ñ¡Ôñ¡°Ð§ÀÍ¡±->¡±AdminServer¡±->¡±ÐÒ顱£¬£¬£¬£¬£¬×÷·Ï¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡£¡£¡£¡£¡£»£»£»£»£»£»
? ÖØÆôWeblogicÏîÄ¿£¬£¬£¬£¬£¬Ê¹ÉèÖÃÉúЧ¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
0x04 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpujul2020.html
0x05 ʱ¼äÏß
2020-07-14 Oracle¹Ù·½Ðû²¼Ç徲ͨ¸æ
2020-07-15 VSRCÐû²¼Îó²îͨ¸æ
