¡¸Îó²îͨ¸æ¡¹WebLogic¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
2020-04-15
Ò»¡¢Îó²î¸ÅÊö
¾©Ê±¼ä4ÔÂ15ÈÕ£¬Oracle¹Ù·½Ðû²¼ÁË2020Äê4ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨Critical Patch Update£©£¬ÐÞ¸´ÁË397¸ö²î±ðˮƽµÄÎó²î¡£ÆäÖаüÀ¨Èý¸öÕë¶ÔWeblogicµÄÑÏÖØÎó²î£¨CVE-2020-2801¡¢CVE-2020-2883¡¢CVE-2020-2884£©ºÍÒ»¸öOracle CoherenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2915£©£¬Ê¹ÓÃÁËOracle Coherence ¿âµÄ²úÆ·ÊÜ´ËÎó²îÓ°Ïì¡£±¾´ÎËĸöÎó²î¾ùΪT3ÐÒé±£´æÈ±ÏÝ¡¢Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´ËÀàÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬CVSSÆÀ·Ö¾ùΪ9.8£¬Ê¹ÓÃÖØÆ¯ºóµÍ¡£½¨ÒéÓû§¾¡¿ì½ÓÄɲ½·¥£¬¶ÔÉÏÊöÎó²î¾ÙÐзÀ»¤¡£
CVE-2020-2801¸´ÏÖÀֳɽØÍ¼£º

²Î¿¼Á´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2020.html
¶þ¡¢Ó°Ïì¹æÄ£
WebLogicÊÜÓ°Ïì°æ±¾£º
- 10.3.6.0.0
- 12.1.3.0.0
- 12.2.1.3.0
- 12.2.1.4.0
CoherenceÊÜÓ°Ïì°æ±¾£º
- 3.7.1.0
- 12.1.3.0.0
- 12.2.1.3.0
- 12.2.1.4.0
×¢£ºÔÚWebLogic Server 11g Release£¨10.3.4£©¼°ÒÔÉϰ汾µÄ×°ÖðüÖÐĬÈϼ¯³É
ÁËOracle Coherence ¿â¡£
Èý¡¢Îó²î¼ì²â
3.1 ÍâµØ¼ì²â
¿ÉʹÓÃÈçÏÂÏÂÁî¶ÔWeblogic°æ±¾ºÍ²¹¶¡×°ÖõÄÇéÐξÙÐÐÅŲ顣
|
1
2
|
$ cd /Oracle/Middleware/wlserver_10.3/server/lib
$ java -cp weblogic.jar weblogic.version
|
ÔÚÏÔʾЧ¹ûÖУ¬ÈôÊÇûÓв¹¶¡×°ÖõÄÐÅÏ¢£¬Ôò˵Ã÷±£´æÎ£º¦£¬ÈçÏÂͼËùʾ£º

3.2 Ô¶³Ì¼ì²â
3.2.1 Nmap·þÎñ̽²â
Nmap¹¤¾ßÌṩÁËWeblogic T3ÐÒéµÄɨÃè¾ç±¾£¬¿É̽²â¿ªÆôT3·þÎñµÄWeblogicÖ÷»ú¡£ÏÂÁîÈçÏ£º
|
1
|
nmap -n -v -Pn –sV [Ö÷»ú»òÍø¶ÎµØµã] -p7001,7002 --script=weblogic-t3-info.nse
|
ÈçÏÂͼºì¿òËùʾ£¬Ä¿µÄ¿ªÆôÁËT3ÐÒéÇÒWeblogic°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£Ö®ÄÚ£¬ÈôÊÇÏà¹ØÖ°Ô±Ã»ÓÐ×°Öùٷ½µÄÇå¾²²¹¶¡£¬Ôò±£´æÎó²îΣº¦¡£

3.2.2 »¥ÁªÍø×ʲúÅŲé
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ìṩ¶Ô»¥ÁªÍø¿ª·ÅÍøÂç×ʲúÐÅÏ¢Éó²éµÄ¹¦Ð§£¬ÆóÒµÓû§¿Éͨ¹ýÔÚNTIÉϼìË÷×ÔÓÐ×ʲúÐÅÏ¢¶Ë¿Ú¿ª·ÅÇéÐΣ¬Éó²éÆóÒµ×ʲúÊÇ·ñÊÜ´ËÎó²îÓ°Ïì¡£

ËÄ¡¢Îó²î·À»¤
4.1 ²¹¶¡¸üÐÂ
OracleÏÖÔÚÒÑÐû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬ÇëÓû§²Î¿¼¹Ù·½Í¨¸æÊµÊ±ÏÂÔØÊÜÓ°Ïì²úÆ·¸üв¹¶¡£¬²¢²ÎÕÕ²¹¶¡×°ÖðüÖеÄreadmeÎļþ¾ÙÐÐ×°ÖøüУ¬ÒÔ°ü¹Üºã¾ÃÓÐÓõķÀ»¤¡£
×¢£ºOracle¹Ù·½²¹¶¡ÐèÒªÓû§³ÖÓÐÕý°æÈí¼þµÄÔÊÐíÕ˺ţ¬Ê¹ÓøÃÕ˺ÅÉϰ¶https://support.oracle.comºó£¬¿ÉÒÔÏÂÔØ×îв¹¶¡¡£
4.2 ÔÝʱ»º½â²½·¥
ÈôÊÇÓû§ÔÝʱÎÞ·¨×°Öøüв¹¶¡£¬¿Éͨ¹ýÏÂÁв½·¥¶ÔÎó²î¾ÙÐÐÔÝʱ·À»¤£º
Óû§¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶ÔʹÓÃT3ÐÒéÎó²îµÄ¹¥»÷¡£Weblogic Server ÌṩÁËÃûΪ weblogic.security.net.ConnectionFilterImpl µÄĬÈÏÅþÁ¬É¸Ñ¡Æ÷£¬´ËÅþÁ¬É¸Ñ¡Æ÷½ÓÊÜËùÓд«ÈëÅþÁ¬£¬¿Éͨ¹ý´ËÅþÁ¬É¸Ñ¡Æ÷ÉèÖùæÔò£¬¶ÔT3¼°T3sÐÒé¾ÙÐлá¼û¿ØÖÆ£¬Ïêϸ²Ù×÷°ì·¨ÈçÏ£º
- ½øÈëWeblogic¿ØÖÆÌ¨£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬½øÈë“Çå¾²”Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷“ɸѡÆ÷”£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖá£

- ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬²Î¿¼ÒÔÏÂд·¨£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÉèÖÃÇÐºÏÆóÒµÏÖÕæÏàÐεĹæÔò£º
|
1
2
3
4
|
127.0.0.1 * * allow t3 t3s
±¾»úIP * * allow t3 t3s
ÔÊÐí»á¼ûµÄIP * * allow t3 t3s
* * * deny t3 t3s
|

ÅþÁ¬É¸Ñ¡Æ÷¹æÔòÃûÌÃÈçÏ£ºtarget localAddress localPort action protocols£¬ÆäÖУº
- target Ö¸¶¨Ò»¸ö»ò¶à¸öҪɸѡµÄ·þÎñÆ÷¡£
- localAddress ¿É½ç˵·þÎñÆ÷µÄÖ÷»úµØµã¡£(ÈôÊÇÖ¸¶¨ÎªÒ»¸öÐǺŠ(*)£¬Ôò·µ»ØµÄÆ¥ÅäЧ¹û½«ÊÇËùÓÐÍâµØ IP µØµã¡£)
- localPort ½ç˵·þÎñÆ÷ÕýÔÚ¼àÌýµÄ¶Ë¿Ú¡£(ÈôÊÇÖ¸¶¨ÁËÐǺţ¬ÔòÆ¥Åä·µ»ØµÄЧ¹û½«ÊÇ·þÎñÆ÷ÉÏËùÓпÉÓõĶ˿Ú)¡£
- action Ö¸¶¨ÒªÖ´ÐеIJÙ×÷¡£(Öµ±ØÐèΪ“allow”»ò“deny”¡£)
- protocols ÊÇÒª¾ÙÐÐÆ¥ÅäµÄÐÒéÃûÁÐ±í¡£(±ØÐèÖ¸¶¨ÏÂÁÐÆäÖÐÒ»¸öÐÒ飺http¡¢https¡¢t3¡¢t3s¡¢giop¡¢giops¡¢dcom »ò ftp¡£) ÈôÊÇδ½ç˵ÐÒ飬ÔòËùÓÐÐÒé¶¼½«ÓëÒ»¸ö¹æÔòÆ¥Åä¡£
- ÉúÑĺóÈô¹æÔòδÉúЧ£¬½¨ÒéÖØÐÂÆô¶¯Weblogic·þÎñ£¨ÖØÆôWeblogic·þÎñ»áµ¼ÖÂÓªÒµÖÐÖ¹£¬½¨ÒéÏà¹ØÖ°Ô±ÆÀ¹ÀΣº¦ºó£¬ÔÙ¾ÙÐвÙ×÷£©¡£ÒÔWindowsÇéÐÎΪÀý£¬ÖØÆô·þÎñµÄ°ì·¨ÈçÏ£º
- ½øÈëÓòËùÔÚĿ¼ÏµÄbinĿ¼£¬ÔÚWindowsϵͳÖÐÔËÐÐstopWebLogic.cmdÎļþÖÕÖ¹weblogic·þÎñ£¬LinuxϵͳÖÐÔòÔËÐÐstopWebLogic.shÎļþ¡£

- ´ýÖÕÖ¹¾ç±¾Ö´ÐÐÍê³Éºó£¬ÔÙÔËÐÐstartWebLogic.cmd»òstartWebLogic.shÎļþÆô¶¯Weblogic£¬¼´¿ÉÍê³ÉWeblogic·þÎñÖØÆô¡£
Èô²Î¿¼ÉÏÊö²Ù×÷ÉèÖÃÁËÅþÁ¬É¸Ñ¡Æ÷ºó£¬µ¼ÖÂWeblogicÎÞ·¨Æô¶¯£¬¿É²Î¿¼“¸½Â¼A Weblogic·þÎñ»Ö¸´”Õ½ڣ¬ÊµÊ±¾ÙÐÐÓªÒµ»Ö¸´¡£
$(".info_chag img").each(function () { $(this).css({ "max-width": "100%","height": "auto","display":"inline-block" }).parent().css({"text-align":"center"}); });
ÄúµÄÁªÏµ·½·¨
? 2025 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

¾ÅÓÎÀϸçÔÆ







