Îó²îͨ¸æ | Oracle Coherence·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐУ¨CVE-2020-2555£©
2020-03-09
Ò»¡¢Îó²îÐÎò
2020Äê1ÔÂ15ÈÕ£¬Oracle¹Ù·½Ðû²¼ÁË2020Äê1ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æ£¬ÐÞ¸´ÁË334¸ö²î±ðˮƽµÄÎó²î¡£ÆäÖаüÀ¨Ò»¸öOracle Coherence·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2555£©£¬CVSSÆÀ·ÖΪ9.8£»¸ÃÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý½á¹¹T3ÍøÂçÐÒéÇëÇó¾ÙÐй¥»÷£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉʵÏÖÔÚÄ¿µÄÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂ롣ʹÓÃÁËOracle Coherence¿âµÄ²úÆ·ÊÜ´ËÎó²îÓ°Ï죬ÔÚWebLogic Server 11g Release£¨10.3.4£©¼°ÒÔÉϰ汾µÄ×°ÖðüÖÐĬÈϼ¯³ÉÁËOracle Coherence¿â¡£
CoherenceÊÇOracle½¨ÉèÒ»Öָ߿ɿ¿ºÍ¸ßÀ©Õ¹¼¯ÈºÅÌËãµÄÒ»¸öÒªº¦²¿¼þ£¬CoherenceÔÚ¿É¿¿µÄ¡¢¸ß¶È¿ÉÉìËõµÄ¶ÔµÈ¼¯ÈºÐÒéÖ®ÉÏÌṩÁ˸´ÖƵġ¢ÂþÑÜʽµÄ£¨·ÖÇøµÄ£©Êý¾ÝÖÎÀí»ººÍ´æ·þÎñ¡£ÏÖÔÚÎó²îϸ½ÚÒѹûÕæ£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¾ÙÐзÀ»¤¡£Îó²î¸´ÏÖÀֳɵĽØÍ¼ÈçÏ£º

²Î¿¼Á´½Ó£º
https://www.oracle.com/security-alerts/cpujan2020.html
https://docs.oracle.com/cd/E18686_01/coh.37/e18692/activecache.htm#COHTU725
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
- Oracle Coherence 3.7.1.17
- Oracle Coherence 12.1.3.0.0
- Oracle Coherence 12.2.1.3.0
- Oracle Coherence 12.2.1.4.0
Èý¡¢Îó²îÆÊÎö
±¾´Î¹Ù·½µÄ²¹¶¡¸üÐÂÐÞ¸´ÁËLimitFilterÀർÖ·´ÐòÁл¯µÄÇå¾²ÎÊÌâ¡£
ÆÊÎöLimitFilterµÄ´úÂë·¢Ã÷ÔÚtoStringÒªÁìÄÚ²¿Å²ÓÃÁËValueExtractorµÄextract ÒªÁ죺

ŲÓÃReflectionExtractorÀàµÄextractÒªÁ죬¿ÉÒÔͨ¹ý´«Èë²ÎÊý·´ÉäÖ´ÐÐÏÂÁÀàËÆÓÚCommonsCollections1µÄGadgetÁ´£º

ËÄ¡¢Îó²î·À»¤
4.1 ×°Öò¹¶¡
ÏÖÔÚ¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·°æ±¾Ðû²¼ÁËÐÞ¸´¸ÃÎó²îµÄÇå¾²²¹¶¡£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì×°ÖþÙÐзÀ»¤£¬ÏÂÔØÁ´½Ó£º
https://support.oracle.com/rs?type=doc&id=2602410.1
4.2 ÔÝʱ»º½â²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨×°ÖÃÐÞ¸´²¹¶¡£¬¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶ÔʹÓÃT3ÐÒéÎó²îµÄ¹¥»÷¡£Weblogic Server ÌṩÁËÃûΪ weblogic.security.net.ConnectionFilterImpl µÄĬÈÏÅþÁ¬É¸Ñ¡Æ÷£¬´ËÅþÁ¬É¸Ñ¡Æ÷½ÓÊÜËùÓд«ÈëÅþÁ¬£¬¿Éͨ¹ý´ËÅþÁ¬É¸Ñ¡Æ÷ÉèÖùæÔò£¬¶Ôt3¼°t3sÐÒé¾ÙÐлá¼û¿ØÖÆ£¬Ïêϸ²Ù×÷°ì·¨ÈçÏ£º
- ½øÈëWeblogic¿ØÖÆÌ¨£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬½øÈë“Çå¾²”Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷“ɸѡÆ÷”£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖá£

- ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺security.net.ConnectionFilterImpl£¬²Î¿¼ÒÔÏÂд·¨£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÉèÖÃÇÐºÏÆóÒµÏÖÕæÏàÐεĹæÔò£º
|
1
2
3
4
5
6
7
|
127.0.0.1 * * allow t3 t3s
±¾»úIP * * allow t3 t3s
ÔÊÐí»á¼ûµÄIP * * allow t3 t3s
* * * deny t3 t3s
|

|
ÅþÁ¬É¸Ñ¡Æ÷¹æÔòÃûÌÃÈçÏ£ºtarget localAddress localPort action protocols£¬ÆäÖУº l target Ö¸¶¨Ò»¸ö»ò¶à¸öҪɸѡµÄ·þÎñÆ÷¡£ l localAddress ¿É½ç˵·þÎñÆ÷µÄÖ÷»úµØµã¡£(ÈôÊÇÖ¸¶¨ÎªÒ»¸öÐǺŠ(*)£¬Ôò·µ»ØµÄÆ¥ÅäЧ¹û½«ÊÇËùÓÐÍâµØ IP µØµã¡£) l localPort ½ç˵·þÎñÆ÷ÕýÔÚ¼àÌýµÄ¶Ë¿Ú¡£(ÈôÊÇÖ¸¶¨ÁËÐǺţ¬ÔòÆ¥Åä·µ»ØµÄЧ¹û½«ÊÇ·þÎñÆ÷ÉÏËùÓпÉÓõĶ˿Ú)¡£ l action Ö¸¶¨ÒªÖ´ÐеIJÙ×÷¡£(Öµ±ØÐèΪ“allow”»ò“deny”¡£) l protocols ÊÇÒª¾ÙÐÐÆ¥ÅäµÄÐÒéÃûÁÐ±í¡£(±ØÐèÖ¸¶¨ÏÂÁÐÆäÖÐÒ»¸öÐÒ飺http¡¢https¡¢t3¡¢t3s¡¢giop¡¢giops¡¢dcom »ò ftp¡£) ÈôÊÇδ½ç˵ÐÒ飬ÔòËùÓÐÐÒé¶¼½«ÓëÒ»¸ö¹æÔòÆ¥Åä¡£ |
- ÉúÑĺóÈô¹æÔòδÉúЧ£¬½¨ÒéÖØÐÂÆô¶¯Weblogic·þÎñ£¨ÖØÆôWeblogic·þÎñ»áµ¼ÖÂÓªÒµÖÐÖ¹£¬½¨ÒéÏà¹ØÖ°Ô±ÆÀ¹ÀΣº¦ºó£¬ÔÙ¾ÙÐвÙ×÷£©¡£ÒÔWindowsÇéÐÎΪÀý£¬ÖØÆô·þÎñµÄ°ì·¨ÈçÏ£º
- ½øÈëÓòËùÔÚĿ¼ÏµÄbinĿ¼£¬ÔÚWindowsϵͳÖÐÔËÐÐcmdÎļþÖÕÖ¹weblogic·þÎñ£¬LinuxϵͳÖÐÔòÔËÐÐstopWebLogic.shÎļþ¡£

- ´ýÖÕÖ¹¾ç±¾Ö´ÐÐÍê³Éºó£¬ÔÙÔËÐÐcmd»òstartWebLogic.shÎļþÆô¶¯Weblogic£¬¼´¿ÉÍê³ÉWeblogic·þÎñÖØÆô¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ







