WebLogic¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-16

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-2891£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬£¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


WebLogic 10.3.6.0.0

WebLogic 12.1.3.0.0

WebLogic 12.2.1.3.0


Îó²î¸ÅÊö


WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÐļþ£¬£¬£¬ £¬£¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽ Web Ó¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦Óà ¡£¡£¡£¡£¡£¡£


Oracle¹Ù·½Ðû²¼ÁË2019Äê10ÔµÄÑÏÖØ²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬£¬£¬ £¬£¬ÆäÖÐÐÞ¸´ÁËWebLogic ±£´æÓÚConsole×é¼þÖеÄÒ»¸ö¸ßΣÎó²î£¨CVE-2019-2891£© ¡£¡£¡£¡£¡£¡£



¹¥»÷ÕßÔÚδÊÚȨµÄÇéÐÎÏ£¬£¬£¬ £¬£¬¿ÉÒÔͨ¹ý·¢ËÍHTTPÇëÇó¹¥»÷WebLogic Server ¡£¡£¡£¡£¡£¡£Ò»µ©Ê¹ÓÃÀֳɣ¬£¬£¬ £¬£¬±ã¿É½ÓÊÜÄ¿µÄµÄWebLogic Server ¡£¡£¡£¡£¡£¡£


¸ÃÎó²îʹÓÃÄÑ¶È½Ï¸ß ¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬ £¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

https://www.oracle.com/technetwork/security-advisory/cpuoct2019verbose-5072833.html