¶¶È¦Îª¶Ä¶øÉú©ɨ²úÎïÏÖÒÑÖ§³ÖWeblogicÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2018-2893¼ì²â

Ðû²¼Ê±¼ä 2018-07-19

2018Äê7ÔÂ17ÈÕOracle¹Ù·½Ðû²¼ÁË7Ô·ݵÄÒªº¦²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬ÆäÖÐÐÞ¸´ÁËÒ»¸öWeblogicÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2018-2893£¨CVSS3.0ÆÀ·Ö£º9.8£©£¬´Ë©¶´ÊǶԱàºÅΪ CVE-2018-2628 ÐÞ¸´µÄÈƹý£¬Í¨¹ýJRMP ЭÒéÀûÓÃRMI»úÖƵÄȱÏݵ½´ïÖ´ÐÐÈÎÒâ·´ÐòÁл¯´úÂëµÄÄ¿µÄ¡£¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿ö϶ԴæÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷£¬Ö´ÐÐÈÎÒâ´úÂë²¢¿É»ñÈ¡Ä¿±êϵͳµÄËùÓÐȨÏÞ¡£


©¶´Ó°Ï췶Χ

 

? WebLogic 10.3.6.0
? WebLogic 12.1.3.0
? WebLogic 12.2.1.2
? WebLogic 12.2.1.3


©¶´¼ì²â

 

¶¶È¦Îª¶Ä¶øÉúÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0ÒÑÓÚ2018Äê7ÔÂ18ÈÕ½ô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐмì²â£¬Óû§Éý¼¶Ì쾵©ɨ²úÎ勇´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺

 

6070°æ±¾Éý¼¶°üΪ607000170£¬Éý¼¶°üÏÂÔصØÖ·£º

/article/type/1/146.html

 

6061°æ±¾Éý¼¶°üΪ6000564£¬Éý¼¶°üÏÂÔصØÖ·£º

/article/type/1/146.html

 

ÇëÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â£¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£
 

©¶´ÐÞ¸´½¨Òé

 

·½°¸Ò»¡¢¹Ø×¢Oracle¹Ù·½CPU¸üв¹¶¡£¨Ê¹ÓÃOracle¹Ù·½Ðí¿ÉÕ˺ŵǽhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlÏÂÔØ×îв¹¶¡£©

 

·½°¸¶þ¡¢¿ØÖÆT3ЭÒéµÄ·ÃÎÊ

´Ë©¶´·¢ÉúÓÚWebLogicµÄT3·þÎñ£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ЭÒéµÄ·ÃÎÊÀ´ÁÙʱ×è¶ÏÕë¶Ô¸Ã©¶´µÄ¹¥»÷¡£µ±¿ª·ÅWebLogic¿ØÖÆ̨¶Ë¿Ú£¨Ä¬ÈÏΪ7001¶Ë¿Ú£©Ê±£¬T3·þÎñ»áĬÈÏ¿ªÆô¡£

 

¾ßÌå²Ù×÷£º

£¨1£©½øÈëWebLogic¿ØÖÆ̨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡ÏҳÃ棬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£

 

£¨2£©ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬0.0.0.0/0 * * deny t3 t3s£¨t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ£©¡£

 

£¨3£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


 

·½°¸Èý¡¢Éý¼¶µ½ jdk-8u20ÒÔÉϵİ汾