WebLogic CVE-2018-2628·´ÐòÁл¯Â©¶´¸´ÏÖ
Ðû²¼Ê±¼ä 2018-04-18Ò»¡¢Â©¶´ÃèÊö
2018Äê4ÔÂ18ÈÕÁ賿£¬Oracle¹Ù·½Ðû²¼ÁË4Ô·ݵÄÄþ¾²²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬¸üÐÂÖÐÐÞ¸´ÁËÒ»¸ö¸ßΣWebLogic·´ÐòÁл¯Â©¶´CVE-2018-2628£¨CNVD-2018-07811¡¢CNNVD-201804-803£©¡£¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ÐÒé¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷£¬²¢¿É»ñÈ¡Ä¿±êϵͳËùÓÐȨÏÞ¡£
Oracle¹Ù·½Ðû²¼µÄ©¶´ÐÅÏ¢ÈçÏÂͼËùʾ£º

¶þ¡¢Â©¶´ÑéÖ¤
¶«Éƽ̨ADLabµÚһʱ¼ä¶ÔCVE-2018-2628½øÐÐÁ˸ú×Ù·ÖÎö£¬²¢Àֳɸ´ÏÖÁ˸鶴¡£¸´ÏÖ½á¹ûÈçÏÂËùʾ£º

Èý¡¢Â©¶´Ó°Ïì
¸Ã©¶´Ó°ÏìWebLogic 10.3.6.0¡¢WebLogic 12.1.3.0¡¢WebLogic 12.2.1.2¡¢WebLogic 12.2.1.3¶à¸ö°æ±¾¡£Ä¿Ç°ÒѾ·¢ÏÖÕë¶Ô¸Ã©¶´µÄÀûÓÃÒªÁ죬ÀûÓÃÒªÁì½ÏΪ¼òµ¥£¬Î£º¦½Ï´ó£¬Ïà¹ØÓû§¼°³§ÉÌÓ¦ÒýÆðÖØÊÓ¡£
ËÄ¡¢Â©¶´ÐÞ¸´
Oracle¹Ù·½ÒÑÐû²¼Õë¶Ô¸Ã©¶´µÄ²¹¶¡£¬¿É¸üйٷ½×îеIJ¹¶¡¡£Oracle¹Ù·½²¹¶¡ÐèÒªÓû§³ÖÓÐÕý°æÈí¼þµÄÐí¿ÉÕʺţ¬Ê¹ÓÃÐí¿ÉÕʺŵǽ https://support.oracle.com ºó£¬¿ÉÒÔÏÂÔØ×îв¹¶¡¡£
¼¸µã½¨Ò飺
1¡¢Éý¼¶JDK°æ±¾¡£ÓÉÓÚJavaÔÚ½ñÄêÒ»Ô·ÝÒÔºó¸üÐÂÁË·´ÐòÁл¯·ÀÓù½Ó¿Ú£¬¿ÉÒÔ»º½â·´ÐòÁл¯Â©¶´µÄÓ°Ïì¡£
2¡¢Éý¼¶WebLogic¡¢É¾³ý²»ÐèÒªµÄÒ³Ã棬ÇåÀí²»Äþ¾²µÄµÚÈý·½¿â¡£
3¡¢½ûÓÃT3ÐÒé¡£
©¶´Á´½Ó£º
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html