2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·£»£»£»£»Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©

Ðû²¼Ê±¼ä 2020-02-21

1.ÖйúÈËÃñÒøÐÐÐû²¼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶>ÐÐÒµ±ê×¼µÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬£¬£¬Ðû²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·(JR/T 0068-2020)£¬£¬£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄÌæ»»ÐÞ¶©°æ±¾¡£¡£¡£¡£ÐÂ°æ¹æ·¶ÓÐÈý¸öÖØµãÐÞ¶©ÄÚÈÝ£º1¡¢Õë¶ÔÐÂÊÖÒÕ·ºÆðºÍÓ¦ÓÃÌá³öÁËеÄÇå¾²ÒªÇó£¨ÀýÈçÔöÌíÁËÐéÄ⻯¡¢ÔÆÅÌËãÇå¾²Ïà¹ØÒªÇ󣬣¬£¬ÔöÌí¹úÃÜSMϵÁÐËã·¨Ïà¹ØµÄÇå¾²ÒªÇ󣬣¬£¬ÔöÌí¶ÔÇå¾²µ¥Î»ºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅÇéÐÎÏà¹ØÒªÇ󣩣»£»£»£»2¡¢¾ÍеÄÓªÒµºÍî¿ÏµÒªÇó¾ÙÐÐÁËÔö²¹ºÍÃ÷È·£¨ÀýÈçÔöÌíÁËÌõÂëÖ§¸¶¡¢ÉúÒâÇå¾²ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÏà¹ØÒªÇ󣩣»£»£»£»3¡¢ÖØÐÂÊáÀí²¢ÌáÉý¹ØÓÚÓªÒµÒ»Á¬ÐÔÓëÔÖÄѻָ´¡¢Çå¾²ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄÇå¾²ÒªÇ󡣡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cebnet.com.cn/20200219/102639904.html


2.˼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷ÌØÈ¨ÕË»§ºÍ¾²Ì¬ÃÜÂ룬£¬£¬½¨ÒéÁ¬Ã¦ÐÞ¸´


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


˼¿ÆÐÞ¸´ÆäÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM£©ÖеÄÌØÈ¨ÕË»§¾²Ì¬ÃÜÂëÎó²î£¬£¬£¬¸ÃÎó²î£¨CVE-2020-3158£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬Ëü¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÈ¨½Ï¸ßµÄÕÊ»§»á¼ûϵͳµÄÃô¸Ð²¿·Ö¡£¡£¡£¡£Ë¼¿ÆÌåÏÖ£¬£¬£¬¡°¸ÃÎó²îÊÇÓÉÓÚijϵͳÕË»§¾ßÓÐĬÈϺ;²Ì¬ÃÜÂëÇÒ²¢²»ÊÜϵͳÖÎÀíÔ±¿ØÖƶøÔì³ÉµÄ¡£¡£¡£¡£¡±SSM On-PremϵͳֻÓÐÔÚÆôÓÃÁ˸߿ÉÓÃÐÔ£¨HA£©¹¦Ð§Ê±²ÅÒ×Êܹ¥»÷£¬£¬£¬µ«¸Ã¹¦Ð§Ä¬ÈÏδÆôÓᣡ£¡£¡£Ë¼¿ÆÖÒÑԳƣ¬£¬£¬¹¥»÷Õß²»ÐèÒªÓÐÓõĵǼ¾Í¿ÉÒÔÌᳫ¹¥»÷£¬£¬£¬²¢ÇÒ¿ÉÒÔʹÓøßÌØÈ¨Ä¬ÈÏÕÊ»§À´ÅþÁ¬Ò×Êܹ¥»÷µÄϵͳ£¬£¬£¬»ñµÃ¶ÔϵͳÊý¾ÝµÄ¶Áд»á¼ûȨÏÞ£¬£¬£¬²¢¸ü¸ÄÆäÉèÖᣡ£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-critical-bug-static-password-in-smart-software-manager-patch-now-says-cisco/


3.AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬ÐÞ¸´Á½¸ö´úÂëÖ´ÐÐÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеÄÁ½¸ö´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£µÚÒ»¸öÎó²î£¨CVE-2020-3764£©Êǿɵ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÔ½½çдÎó²î£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe Media Encoder 14.0¼°¸üÔç°æ±¾¡£¡£¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2020-3765£©Ò²ÊÇÓÉÔ½½çдµ¼ÖµĴúÂëÖ´ÐÐÎó²î£¬£¬£¬µ«¹¥»÷Ö»ÄÜÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖоÙÐУ¬£¬£¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe After Effects°æ±¾16.1.2¼°¸üÔç°æ±¾¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-releases-out-of-schedule-fixes-for-critical-vulnerabilities/


4.Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Apache TomcatЧÀÍÆ÷±£´æÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¶ÁÈ¡»ò°üÀ¨TomcatÉÏËùÓÐwebappĿ¼ÏµÄí§ÒâÎļþ£¬£¬£¬È磺webappÉèÖÃÎļþ»òÔ´´úÂëµÈ¡£¡£¡£¡£¸ÃÎó²îÓëTomcat AJPЭÒéÓйأ¬£¬£¬Tomcat AJP ConnectorĬÈÏÉèÖÃϼ´Îª¿ªÆô״̬£¬£¬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËTomcat 6/7/8/9È«°æ±¾£¬£¬£¬Apache¹Ù·½ÒÑÐû²¼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´ËÎó²î¾ÙÐÐÐÞ¸´£¬£¬£¬½¨ÒéÓû§ÏÂÔØÊ¹Óᣡ£¡£¡£ÓÉÓÚTomcat 6ÒѾ­×èֹά»¤£¬£¬£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâÊܹ¥»÷¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487


5.ÃÀ¹ú²ÎÒéÔ±Ìá³öÐÂÊý¾Ý±£»£»£»£»¤·¨°¸£¬£¬£¬½¨Ò齨ÉèÊý¾Ý±£»£»£»£»¤¾Ö


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹úŦԼÖݲÎÒéÔ±¼ª¶û˹²¼À¼µÂ£¨Kirsten Gillibrand£©ÉÏÖÜÐû²¼ÁËÒ»ÏîÁ¢·¨²Ý°¸£¬£¬£¬¸Ã·¨°¸½«½¨ÉèÒ»¸ö×ÔÁ¦µÄÁª°î»ú¹¹£¬£¬£¬¼´Êý¾Ý±£»£»£»£»¤¾Ö£¬£¬£¬Ö¼ÔÚ½ç˵¡¢ÖٲúÍÖ´ÐÐÊý¾Ý±£»£»£»£»¤¹æÔò¡£¡£¡£¡£Õâλ²ÎÒéÔ±ÒÔΪ£¬£¬£¬¡¶Áª°îÉÌҵίԱ»á·¨¡·²¢Î´½â¾öÊý¾Ý±£»£»£»£»¤·½ÃæµÄÌôÕ½£¬£¬£¬¶øÃÀ¹úÔÚÓ¦¶ÔÊý¾Ý±£»£»£»£»¤ÌôÕ½ºÍÊý×Öʱ´úµÄÐí¶àÆäËüÌôÕ½·½ÃæÂäÎ飬£¬£¬ÃÀ¹úҲûÓÐÒ»¸öרÃŵĻú¹¹À´Ö´ÐÐÊý¾ÝÒþ˽¹æÔò¡£¡£¡£¡£ÈôÊǸ÷¨°¸»ñµÃͨ¹ý£¬£¬£¬½«ÊÊÓÃÓÚÈκÎÊÕÈëÁè¼Ý2500ÍòÃÀÔª£¬£¬£¬»òÖÎÀí5Íò»ò¸ü¶àÈ˵ÄСÎÒ˽¼ÒÊý¾ÝµÄ¹«Ë¾¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/us-senator-proposes-new-data-protection-bill-37232e0b


6.¸çÂ×±ÈÑÇCommunity CareÔâÀÕË÷¹¥»÷£¬£¬£¬»¼ÕßÊý¾Ý¿ÉÄÜй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¸çÂ×±ÈÑÇÊ×¶¼µØÇø×î´óµÄ×ÔÁ¦Ò½ÁÆ»ú¹¹Community Care»¼ÕßÊý¾Ý¿ÉÄÜй¶£¬£¬£¬¸ÃÊÂÎñÊÇÓÉÆä»á¼ÆÊ¦ÊÂÎñËùBSTÔâµ½ÀÕË÷Èí¼þ¹¥»÷µ¼ÖµÄ¡£¡£¡£¡£BSTÓÚ2019Äê12ÔÂ7ÈÕ·¢Ã÷°üÀ¨¿Í»§»á¼ÆºÍ˰ÊÕÊý¾ÝÔÚÄڵIJ¿·ÖÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬£¬£¬µ«¸Ã¹«Ë¾Äܹ»Ê¹Óñ¸·Ý»¹Ô­Îļþ¡£¡£¡£¡£ÔÚÖ®ºóµÄÊÓ²ìÖУ¬£¬£¬¸Ã¹«Ë¾ÓÚ2ÔÂ5ÈÕÈ·Èϲ¿·Ö»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶£¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÉúÈÕ¡¢ÌõÄ¿ºÅÂëºÍÕʵ¥´úÂ룬£¬£¬µ«²»°üÀ¨ÒøÐÐÕʺš¢Éç»áÇå¾²ºÅÂëºÍ²¡ÀúÐÅÏ¢¡£¡£¡£¡£BST»òCommunity Care¶¼Ã»ÓÐ͸¶ÊÜÓ°ÏìµÄ»¼ÕßÈËÊý¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://dailygazette.com/article/2020/02/19/data-breach-community-Care-physicians