WebLogic í§ÒâÎļþÉÏ´«Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-19CVE-2018-2894 ³§ÉÌ×ÔÆÀ£º9.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
ÊÜÓ°Ïì°æ±¾£º
WebLogic 10.3.6.0
WebLogic 12.1.3.0
WebLogic 12.2.1.2
WebLogic 12.2.1.3
Oracle¹Ù·½Ðû²¼ÁË7Ô·ݵÄÒªº¦²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬ÆäÖÐÕë¶Ô¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐеĸßΣÎó²î CVE-2018-2894 ¾ÙÐÐÐÞ¸´£ºhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html¡£
½ñÌì7ÔÂ19ºÅ¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄCNCERT·¢³öͨ¸æ£¬Ö¸³öCVE-2018-2894ʵÖÊÉÏΪí§ÒâÎļþÉÏ´«Îó²î£ºhttps://mp.weixin.qq.com/s/y5JGmM-aNaHcs_6P9a-gRQ¡£
WebLogicÖÎÀí¶ËδÊÚȨµÄÁ½¸öÒ³Ãæ±£´æí§ÒâÉÏ´«getshellÎó²î£¬¿ÉÖ±½Ó»ñȡȨÏÞ¡£Á½¸öÒ³Ãæ»®·ÖΪ/ws_utc/begin.do£¬/ws_utc/config.do¡£
ws_utcΪWebLogic Web·þÎñ²âÊÔ¿Í»§¶Ë£¬ÆäÉèÖÃÒ³Ãæ±£´æÎ´ÊÚȨ»á¼ûµÄÎÊÌ⣬·¾¶Îª/ws_utc/config.do¡£
¹¥»÷Õßͨ¹ýʹÓôËÎó²î£¬¼´¿ÉÔÚÔ¶³ÌÇÒδ¾ÊÚȨµÄÇéÐÎÏÂÔÚWebLogic·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£
1. ´ËÎó²îʵÖÊÊÇÎļþÉÏ´«£¬Ê¹ÓÃ×ðÁú¿Ê±Çå¾²²úÆ·µÄ¿Í»§ÎÞÐèÉý¼¶²¹¶¡¼´¿É·ÀÓùwebshellÉÏ´«¡£
2. ʹÓÃOracle¹Ù·½Çå¾²²¼¶¡¾ÙÐиüÐÂÐÞ¸´£ºhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html¡£
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
https://mp.weixin.qq.com/s/y5JGmM-aNaHcs_6P9a-gRQ


¾©¹«Íø°²±¸11010802024551ºÅ