¡¾Â©¶´¾¯¸æ¡¿weblogic·´ÐòÁл¯Â©¶´ÔÙ¶ÈÀ´Ï®

Ðû²¼Ê±¼ä 2018-04-18

¶ÔÓÚʹÓÃÖмä¼þ¿ª·¢µÄÓû§À´Ëµ£¬WeblogicÒѾ­ËãÊǸöÃ÷ÐÇÁË£¬¶øweblogic¿ò¼ÜÖÐʹÓõÄÐòÁл¯ºÍ·´ÐòÁл¯¼¼ÊõÓÖ½«ËüÍÆµ½Á˸ßΣ²úÎïµÄ·ç¿ÚÀ˼⣬³ÉΪºÚ¿Í¡¢¶ñÒâ¹¥»÷Õß¡¢·Ç·¨ÍÚ¿óÕßµÄÀûÆ÷£¬2018Äê4ÔÂ18ÈÕÁ賿£¬ÓÖһö±àºÅΪCVE-2018-2628µÄweblogic©¶´±»±¬³ö¡£ ÒÔÏÂΪ¶Ô¸Ã©¶´µÄ±¨µÀ£º



©¶´ÏìӦʱ¼äÖá


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÊÜÓ°Ïì»·¾³¼ò½é


WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplication server£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖмä¼þ£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦Ó÷þÎñÆ÷¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJava Enterprise³ß¶ÈµÄÄþ¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀíÖ®ÖС£



©¶´ÃèÊö


Oracle WebLogic ServerµÄ WLSºËÐÄ×é¼þÖдæÔÚÄþ¾²Â©¶´¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú·¢Ë͵½TCP 7001¶Ë¿ÚµÄT3ЭÒéÁ÷Á¿ÖÐÌØÖÆµÄÐòÁл¯Java¹¤¾ß£¬ÀûÓøÃ©¶´Ö´ÐÐÈÎÒâÃüÁî¡£


Ó°Ïì°æ±¾£º


Weblogic 10.3.6.0

Weblogic 12.1.3.0

Weblogic 12.2.1.2

Weblogic 12.2.1.3



©¶´¸´ÏÖ


¹¹½¨POC£¬¶ÔÄ¿±ê»úÆ÷·¢Ëͼì²âÊý¾Ý£¬ÑéÖ¤½á¹ûÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


©¶´´¥·¢¹ý³Ì


µÚÒ»²½£ºÓ¦ÓÃT3ЭÒéÓëÄ¿±ê»úÆ÷½¨Á¢Á¬½Ó£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÚ¶þ²½£º·¢ËͽṹµÄÇëÇóÊý¾Ý£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÚÈý²½£ºÆ¾¾ÝÅжÏÄ¿±ê»úÆ÷·µ»ØµÄÊý¾ÝÀ´È·¶¨ÊÇ·ñ´æÔÚ©¶´¡£



²úÎï½â¾ö·½°¸


¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèºÍ¹ÜÀíϵͳµÚһʱ¼äÌí¼ÓÁËÕë¶Ô¸Ã©¶´µÄ¼ì²âÒªÁ죬Ç뼰ʱÉý¼¶µ½Éý¼¶ÖÁ607000152-607000153Éý¼¶°ü£¬¶Ô¸Ã©¶´½øÐÐɨÃè¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Éý¼¶°üÏÂÔØÁ´½Ó£º

http://www.venustech.com.cn/DownFile/575/



¹ØÁªÂ©¶´Ö§³ÖÇé¿ö


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



¹ØÓÚ¶«É­Æ½Ì¨


¶«É­Æ½Ì¨Â©É¨²úÎïÖÐÐľ۽¹ÓÚÍøÂç×ʲú¼°·þÎñµÄÄþ¾²ÆÀ¹À¡¢¼ì²âºÍÐÞ¸´ £»Ñз¢ÁËÕë¶ÔÄþ¾²·çÏÕ¸÷¸ö½×¶ÎµÄÄþ¾²²úÎï¼°·þÎñ £»²úÎï°üÂÞ£ºÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ¡¢Ìì¾µwebÓ¦Óüì²âϵͳ¡¢Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ-¹¤¿Ø×¨Óð桢¹¤¿ØÎÞËðÆÀ¹Àϵͳ¡¢Â©¶´ÐÞ¸´¹ÜÀíϵͳ¡¢Â©¶´¹ÜÀíϵͳ¡¢¹¤¿ØÂ©¶´ÍÚ¾òϵͳ £»Äþ¾²·þÎñ°üÂÞ£ºÍøÕ¾¼à¿Ø·þÎñ¡¢Ó¦¼±¹¤¾ßÏä·þÎñ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



¶ÔÓÚʹÓÃÖмä¼þ¿ª·¢µÄÓû§À´Ëµ£¬WeblogicÒѾ­ËãÊǸöÃ÷ÐÇÁË£¬¶øweblogic¿ò¼ÜÖÐʹÓõÄÐòÁл¯ºÍ·´ÐòÁл¯¼¼ÊõÓÖ½«ËüÍÆµ½Á˸ßΣ²úÎïµÄ·ç¿ÚÀ˼⣬³ÉΪºÚ¿Í¡¢¶ñÒâ¹¥»÷Õß¡¢·Ç·¨ÍÚ¿óÕßµÄÀûÆ÷£¬2018Äê4ÔÂ18ÈÕÁ賿£¬ÓÖһö±àºÅΪCVE-2018-2628µÄweblogic©¶´±»±¬³ö¡£ ÒÔÏÂΪ¶Ô¸Ã©¶´µÄ±¨µÀ£º



©¶´ÏìӦʱ¼äÖá




ÊÜÓ°Ïì»·¾³¼ò½é


WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplication server£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖмä¼þ£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦Ó÷þÎñÆ÷¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJava Enterprise³ß¶ÈµÄÄþ¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀíÖ®ÖС£



©¶´ÃèÊö


Oracle WebLogic ServerµÄ WLSºËÐÄ×é¼þÖдæÔÚÄþ¾²Â©¶´¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú·¢Ë͵½TCP 7001¶Ë¿ÚµÄT3ЭÒéÁ÷Á¿ÖÐÌØÖÆµÄÐòÁл¯Java¹¤¾ß£¬ÀûÓøÃ©¶´Ö´ÐÐÈÎÒâÃüÁî¡£


Ó°Ïì°æ±¾£º


Weblogic 10.3.6.0

Weblogic 12.1.3.0

Weblogic 12.2.1.2

Weblogic 12.2.1.3



©¶´¸´ÏÖ


¹¹½¨POC£¬¶ÔÄ¿±ê»úÆ÷·¢Ëͼì²âÊý¾Ý£¬ÑéÖ¤½á¹ûÈçÏ£º



©¶´´¥·¢¹ý³Ì


µÚÒ»²½£ºÓ¦ÓÃT3ЭÒéÓëÄ¿±ê»úÆ÷½¨Á¢Á¬½Ó£º



µÚ¶þ²½£º·¢ËͽṹµÄÇëÇóÊý¾Ý£º



µÚÈý²½£ºÆ¾¾ÝÅжÏÄ¿±ê»úÆ÷·µ»ØµÄÊý¾ÝÀ´È·¶¨ÊÇ·ñ´æÔÚ©¶´¡£



²úÎï½â¾ö·½°¸


¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèºÍ¹ÜÀíϵͳµÚһʱ¼äÌí¼ÓÁËÕë¶Ô¸Ã©¶´µÄ¼ì²âÒªÁ죬Ç뼰ʱÉý¼¶µ½Éý¼¶ÖÁ607000152-607000153Éý¼¶°ü£¬¶Ô¸Ã©¶´½øÐÐɨÃè¡£



Éý¼¶°üÏÂÔØÁ´½Ó£º

http://www.venustech.com.cn/DownFile/575/



¹ØÁªÂ©¶´Ö§³ÖÇé¿ö




¹ØÓÚ¶«É­Æ½Ì¨


¶«É­Æ½Ì¨Â©É¨²úÎïÖÐÐľ۽¹ÓÚÍøÂç×ʲú¼°·þÎñµÄÄþ¾²ÆÀ¹À¡¢¼ì²âºÍÐÞ¸´ £»Ñз¢ÁËÕë¶ÔÄþ¾²·çÏÕ¸÷¸ö½×¶ÎµÄÄþ¾²²úÎï¼°·þÎñ £»²úÎï°üÂÞ£ºÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ¡¢Ìì¾µwebÓ¦Óüì²âϵͳ¡¢Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ-¹¤¿Ø×¨Óð桢¹¤¿ØÎÞËðÆÀ¹Àϵͳ¡¢Â©¶´ÐÞ¸´¹ÜÀíϵͳ¡¢Â©¶´¹ÜÀíϵͳ¡¢¹¤¿ØÂ©¶´ÍÚ¾òϵͳ £»Äþ¾²·þÎñ°üÂÞ£ºÍøÕ¾¼à¿Ø·þÎñ¡¢Ó¦¼±¹¤¾ßÏä·þÎñ¡£