¡¾Ô­´´Â©¶´¡¿Oracle WebLogic Ô¶³ÌÃüÁîÖ´ÐЩ¶´£¨¼´CVE-2019-2725²¹¶¡Èƹý£©

Ðû²¼Ê±¼ä 2019-06-17
0x01 ©¶´ÃèÊö


2019Äê4ÔÂ26ÈÕ £¬Oracle¹Ù·½Ðû²¼ÁËWebLogic wls9-async¼°wls-wsat×é¼þÔ¶³ÌÃüÁîÖ´ÐЩ¶´µÄ²¹¶ ¡£¨CVE-2019-2725£© £¬https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html ¡£


¶«É­Æ½Ì¨ADLabµÚһʱ¼ä¶Ô¸Ã²¹¶¡½øÐÐÁËÉîÈëÑо¿ £¬·¢Ïָò¹¶¡´æÔÚÄþ¾²È±ÏÝ £¬ÔڵͰ汾JDKµÄ»·¾³ÖпÉÒÔ±»Èƹýµ¼ÖÂÈÎÒâÔ¶³ÌÃüÁîÖ´ÐÐ ¡£ADLabÒÑÏòOracle¹Ù·½·´À¡ÁËCVE-2019-2725²¹¶¡ÈƹýµÄ©¶´ £¬²¢µÃµ½Á˹ٷ½¼òÖ±ÈÏ ¡£ÓÉÓڸ鶴ÄÜʹ¹¥»÷ÕßÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁî £¬Ä¿Ç°¹Ù·½²¹¶¡ÉÐδÐû²¼ÇÒÒÑÓÐÓû§Êܵ½ÒÉËƸ鶴µÄ¹¥»÷ £¬½¨ÒéËùÓÐʹÓÃOracle WebLogicµÄÓû§¾¡¿ìÖ÷¶¯²¿ÊðÏàÓ¦·À»¤ ¡£


0x02 ©¶´Ê±¼äÖá


2019Äê6ÔÂ12ÈÕ £¬ADLab½«Â©¶´ÏêÇéÌá½»¸øOracle¹Ù·½£»


2019Äê6ÔÂ14ÈÕ £¬Oracle¹Ù·½È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼ÐÞ¸´ ¡£


0x03 Ó°Ïì°æ±¾


Oracle WebLogic Server 10.3.6.0


0x04 ©¶´ÀûÓÃ


²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0 + CVE-2019-2725²¹¶¡


ÀûÓùý³Ì£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



0x05 ÁÙʱ½â¾ö·½°¸


¹Ù·½²¹¶¡Ç°µÄÁÙʱ·À»¤£º


ɾ³ýwls9_async_response.war¡¢wls_wsat.war¼°Ïà¹ØÎļþ¼Ð £¬²¢ÖØÆôweblogic·þÎñ ¡£


½ûÖ¹_async/*¼°wls-wsat/*ÐÎʽµÄURL·¾¶·ÃÎÊ ¡£


ʹÓÃ1.7¼°ÒÔÉϵÄjava°æ±¾ÔËÐÐWebLogic£¨Õë¶ÔÄ¿Ç°Á÷´«µÄµÍ°æ±¾JDKÀûÓã© ¡£