WeblogicÔÙ±¬¸ßΣÎó²î ÈËÉú¾ÍÊDz©Ìṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2019-10-17
2019Äê10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬Oracle¹Ù·½Ðû²¼10Ô·ÝÇå¾²²¹¶¡, ÆäÖаüÀ¨ÁËÈËÉú¾ÍÊDz©ADLab·¢Ã÷²¢Ìá½»¸ø¹Ù·½µÄÁ½¸öÇå¾²Îó²î ¡£¡£



CVE-2019-2890 £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýT3ЭÒé¶Ô±£´æ¸ÃÎó²îµÄWebLogic×é¼þʵÑéÔ¶³Ìí§Òâ´úÂë¹¥»÷£»£»£»


CVE-2019-2887£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýT3ЭÒé¶Ô±£´æ¸ÃÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷ ¡£¡£


Îó²îÓ°Ïì°æ±¾



WebLogic Server 10.3.6.0
WebLogic Server 12.1.3.0
WebLogic Server 12.2.1.3



Îó²îʹÓÃ



Çå¾²Îó²î£ºCVE-2019-2890
²âÊÔÇéÐΣºWebLogic Server 10.3.6.0
Îó²îʹÓÃЧ¹û£º

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

Çå¾²Îó²î£ºCVE-2019-2887
²âÊÔÇéÐΣºWebLogic Server 10.3.6.0
Îó²îʹÓÃЧ¹û:  

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



½â¾ö¼Æ»®



? Éý¼¶¹Ù·½²¹¶¡
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

? ²úÆ·¼ì²âÓë·À»¤
ÒѰ²ÅÅÈËÉú¾ÍÊDz©IDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æÔòÒѾ­Ï·¢²¢Ó¦Ó㬣¬£¬£¬£¬£¬¼´¿ÉÓÐÓüì²â»ò×è¶Ï¹¥»÷£º 


TCP_Oracle_WebLogic_·´ÐòÁл¯Îó²î[CVE-2019-2890] 
HTTP_WebLogic_XXE×¢ÈëÎó²î[CVE-2019-2887]

£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

£¨3£©ÌìÇåWebÓ¦ÓÃÇå¾²Íø¹Ø±¨¾¯½ØÍ¼£º

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Îó²îɨÃè


ÈËÉú¾ÍÊDz©Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2019Äê10ÔÂ17ÈÕ½ôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬£¬£¬£¬£¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐмì²â£¬£¬£¬£¬£¬£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ·Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃè ¡£¡£


6070°æ±¾Éý¼¶°üΪ607000250£¬£¬£¬£¬£¬£¬Éý¼¶°üÏÂÔØµØµã£º
/article/type/1/146.html

ÇëÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬£¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â£¬£¬£¬£¬£¬£¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥ ¡£¡£

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø