¡¾Ô´´Â©¶´¡¿WebLogic Blind XXE©¶´Í¨¸æ£¨CVE-2020-14820£©
Ðû²¼Ê±¼ä 2020-10-22©¶´¸ÅÊö
Oracle¹Ù·½Ðû²¼ÁË10Ô·ݵÄÄþ¾²²¹¶¡, ²¹¶¡ÖаüÂÞ¶¶È¦Îª¶Ä¶øÉúADLab·¢ÏÖ²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄ©¶´£¬Â©¶´±àºÅΪCVE-2020-14820¡£Í¨¹ý¸Ã©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3»òIIOPÐÒéÖУ¬Í¨¹ý¶ÔÐÒéÖеÄpayload½øÐз´ÐòÁл¯£¬´Ó¶øÊµÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷¡£
©¶´Ê±¼äÖá
2020Äê5ÔÂ11ÈÕ£¬ADLab½«Â©¶´ÏêÇéÌá½»¸øOracle¹Ù·½£»
2020Äê5ÔÂ12ÈÕ£¬Oracle¹Ù·½È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼×ÅÊÖÐÞ¸´£»
2020Äê10ÔÂ21ÈÕ£¬Oracle¹Ù·½Ðû²¼Äþ¾²²¹¶¡¡£
ÊÜÓ°Ïì°æ±¾
Weblogic 10.3.6.0.0
Weblogic 12.1.3.0.0
Weblogic 12.2.1.3.0
Weblogic 12.2.1.4.0
Weblogic 14.1.1.0.0
©¶´ÀûÓÃ
²âÊÔ»·¾³£ºWebLogicServer 10.3.6.0.0
©¶´ÀûÓÃЧ¹û£º
¹æ±Ü·½°¸
1¡¢Éý¼¶²¹¶¡
https://www.oracle.com/security-alerts/cpuoct2020.html
2¡¢¿ØÖÆT3ÐÒéµÄ·ÃÎÊ
¾ßÌå²Ù×÷£º
1£©½øÈëWebLogic¿ØÖÆÌ¨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£
2)ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£
3£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£
3¡¢½ûÖ¹ÆôÓÃIIOPÐÒé
µÇ½WebLogic¿ØÖÆÌ¨£¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer
¶¶È¦Îª¶Ä¶øÉú»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©
DLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØÖ¹Ä¿Ç°£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´900Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØÏµÍ³Äþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£