¡¾Ô­´´Îó²î¡¿WebLogic Blind XXEÎó²î£¨CVE-2019-2887£©

Ðû²¼Ê±¼ä 2019-10-16

Îó²î¸ÅÊö


Oracle¹Ù·½Ðû²¼10Ô·ÝÇå¾²²¹¶¡, ²¹¶¡ÖаüÀ¨Z6×ðÁú¿­Ê±ADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÎó²î £¬£¬£¬£¬£¬Îó²î±àºÅΪCVE-2019-2887¡£¡£¡£¡£¡£¡£¡£Ê¹ÓøÃÎó²î £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýT3ЭÒé¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£¡£¡£¡£¡£


Îó²îʱ¼äÖá


2019Äê5ÔÂ15ÈÕ £¬£¬£¬£¬£¬ADLab½«Îó²îÏêÇéÌá½»¸øOracle¹Ù·½£»£»£»£»

2019Äê5ÔÂ16ÈÕ £¬£¬£¬£¬£¬Oracle¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´£»£»£»£»

2019Äê10ÔÂ15ÈÕ £¬£¬£¬£¬£¬Oracle¹Ù·½·ÖÅÉCVE±àºÅ²¢Ðû²¼Çå¾²²¹¶¡¡£¡£¡£¡£¡£¡£¡£


Îó²îÓ°Ïì°æ±¾


WebLogic Server 10.3.6.0

WebLogic Server 12.1.3.0

WebLogic Server 12.2.1.3

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£


Îó²îʹÓÃ


²âÊÔÇéÐΣºWebLogic Server 10.3.6.0


Îó²îʹÓÃЧ¹û


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


¹æ±Ü¼Æ»®


1¡¢Éý¼¶²¹¶¡

https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html


2¡¢¿ØÖÆT3ЭÒéµÄ»á¼û

´ËÎó²î±¬·¢ÓÚWebLogicµÄT3ЧÀÍ £¬£¬£¬£¬£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ЭÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶Ô¸ÃÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£µ±¿ª·ÅWebLogic¿ØÖÆÌ¨¶Ë¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê± £¬£¬£¬£¬£¬T3ЧÀÍ»áĬÈÏ¿ªÆô¡£¡£¡£¡£¡£¡£¡£


Ïêϸ²Ù×÷£º


a£©½øÈëWebLogic¿ØÖÆÌ¨ £¬£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖÐ £¬£¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ £¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡± £¬£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£¡£¡£¡£¡£

b£©ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl £¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s £¬£¬£¬£¬£¬0.0.0.0/0 * * deny t3 t3s£¨t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û£©¡£¡£¡£¡£¡£¡£¡£

c£©ÉúÑĺóÐèÖØÐÂÆô¶¯ £¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£¡£¡£¡£¡£


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾