¡¾Ô´´Îó²î¡¿WebLogic Blind XXEÎó²îͨ¸æ£¨CVE-2020-14820£©
Ðû²¼Ê±¼ä 2020-10-22Îó²î¸ÅÊö
Oracle¹Ù·½Ðû²¼ÁË10Ô·ݵÄÇå¾²²¹¶¡, ²¹¶¡ÖаüÀ¨ÈËÉú¾ÍÊDz©ADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÎó²î£¬£¬£¬£¬£¬Îó²î±àºÅΪCVE-2020-14820¡£¡£Í¨¹ý¸ÃÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3»òIIOPÐÒéÖУ¬£¬£¬£¬£¬Í¨¹ý¶ÔÐÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£
Îó²îʱ¼äÖá
2020Äê5ÔÂ11ÈÕ£¬£¬£¬£¬£¬ADLab½«Îó²îÏêÇéÌá½»¸øOracle¹Ù·½£»£»£»£»£»£»
2020Äê5ÔÂ12ÈÕ£¬£¬£¬£¬£¬Oracle¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´£»£»£»£»£»£»
2020Äê10ÔÂ21ÈÕ£¬£¬£¬£¬£¬Oracle¹Ù·½Ðû²¼Çå¾²²¹¶¡¡£¡£
ÊÜÓ°Ïì°æ±¾
Weblogic 10.3.6.0.0
Weblogic 12.1.3.0.0
Weblogic 12.2.1.3.0
Weblogic 12.2.1.4.0
Weblogic 14.1.1.0.0
![]()
Îó²îʹÓÃ
²âÊÔÇéÐΣºWebLogicServer 10.3.6.0.0
Îó²îʹÓÃЧ¹û£º

¹æ±Ü¼Æ»®
1¡¢Éý¼¶²¹¶¡
https://www.oracle.com/security-alerts/cpuoct2020.html
2¡¢¿ØÖÆT3ÐÒéµÄ»á¼û
Ïêϸ²Ù×÷£º
1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£
2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£
3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£

3¡¢Õ¥È¡ÆôÓÃIIOPÐÒé
Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

ÈËÉú¾ÍÊDz©Æð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
DLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î½ü1100¸ö£¬£¬£¬£¬£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î900Óà¸ö£¬£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØÏµÍ³Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵ȡ£¡£



¾©¹«Íø°²±¸11010802024551ºÅ