¶¶È¦Îª¶Ä¶øÉú©ɨ²úÎïÏÖÒÑÖ§³ÖWeblogicÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2018-2893¼ì²â
Ðû²¼Ê±¼ä 2018-07-192018Äê7ÔÂ17ÈÕOracle¹Ù·½Ðû²¼ÁË7Ô·ݵÄÒªº¦²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬ÆäÖÐÐÞ¸´ÁËÒ»¸öWeblogicÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2018-2893£¨CVSS3.0ÆÀ·Ö£º9.8£©£¬´Ë©¶´ÊǶԱàºÅΪ CVE-2018-2628 ÐÞ¸´µÄÈƹý£¬Í¨¹ýJRMP ÐÒéÀûÓÃRMI»úÖƵÄȱÏݵ½´ïÖ´ÐÐÈÎÒâ·´ÐòÁл¯´úÂëµÄÄ¿µÄ¡£¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿ö϶ԴæÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷£¬Ö´ÐÐÈÎÒâ´úÂë²¢¿É»ñÈ¡Ä¿±êϵͳµÄËùÓÐȨÏÞ¡£
©¶´Ó°Ï췶Χ
? WebLogic 10.3.6.0
? WebLogic 12.1.3.0
? WebLogic 12.2.1.2
? WebLogic 12.2.1.3
©¶´¼ì²â
¶¶È¦Îª¶Ä¶øÉúÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0ÒÑÓÚ2018Äê7ÔÂ18ÈÕ½ô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐмì²â£¬Óû§Éý¼¶Ì쾵©ɨ²úÎ勇´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000170£¬Éý¼¶°üÏÂÔصØÖ·£º
6061°æ±¾Éý¼¶°üΪ6000564£¬Éý¼¶°üÏÂÔصØÖ·£º
ÇëÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â£¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£
©¶´ÐÞ¸´½¨Òé
·½°¸Ò»¡¢¹Ø×¢Oracle¹Ù·½CPU¸üв¹¶¡£¨Ê¹ÓÃOracle¹Ù·½Ðí¿ÉÕ˺ŵǽhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlÏÂÔØ×îв¹¶¡£©
·½°¸¶þ¡¢¿ØÖÆT3ÐÒéµÄ·ÃÎÊ
´Ë©¶´·¢ÉúÓÚWebLogicµÄT3·þÎñ£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ·ÃÎÊÀ´ÁÙʱ×è¶ÏÕë¶Ô¸Ã©¶´µÄ¹¥»÷¡£µ±¿ª·ÅWebLogic¿ØÖÆ̨¶Ë¿Ú£¨Ä¬ÈÏΪ7001¶Ë¿Ú£©Ê±£¬T3·þÎñ»áĬÈÏ¿ªÆô¡£
¾ßÌå²Ù×÷£º
£¨1£©½øÈëWebLogic¿ØÖÆ̨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡ÏҳÃ棬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£
£¨2£©ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬0.0.0.0/0 * * deny t3 t3s£¨t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ£©¡£
£¨3£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£
·½°¸Èý¡¢Éý¼¶µ½ jdk-8u20ÒÔÉϵİ汾