2020-10-20
Ðû²¼Ê±¼ä 2020-10-21ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_MidaSolutionseFramework_ajaxreq.phpÃüÁî×¢È멶´ [CVE-2020-15920][CNNVD-202007-1517] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Mida SolutionsÊÇÒ»¼ÒרעÓÚͳһͨÐÅ(UC)µÄ¸ß¼¼ÄÜÒâ´óÀû¹«Ë¾,MidaÍŶÓÒѳÉΪͳһÐ×÷ºÍרҵÏàͬµÄÈ«ÇòÁìµ¼Õß,¼¸ºõËùÓÐÐÐÒµµÄ·þÎñÌṩÉÌ£¬ÏµÍ³¼¯³ÉÉÌ¡£ÆäºÏ×÷»ï°éÓÐ΢Èí,˼¿Æ,»ÝÆÕ,ÖйúµçÐŵÈ40¸öÊÀ½çÖªÃûÆóÒµ¡£Mida eFrameworkÊÇMida Solutions¹«Ë¾ÆìÏÂÊÓƵºÍÓïÒôÓ¦Ó÷¨Ê½µÄÍêÕû·þÎñÌ×¼þ£¬Ó뼸ºõËùÓÐÖ÷ÒªµÄUCƽ̨¼æÈÝ¡£¸ÃÌ×¼þ°üÂÞ»°ÎñÔ±¿ØÖÆ̨£¬¼Ç¼Æ÷£¬´«Õæ·þÎñÆ÷£¬¼Æ·Ñ£¬ÐÐÁйÜÀíÆ÷£¬×Ô¶¯»°ÎñÔ±£¬Òƶ¯Ó¦Ó÷¨Ê½£¬µç»°·þÎñ¡£ |
¸üÐÂʱ¼ä£º | 20201020 |
ʼþÃû³Æ£º | TCP_Java·´ÐòÁл¯_MozillaRhino1_ÀûÓÃÁ´¹¥»÷ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃMozillaRhino1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ. rhinoÊÇʹÓÃjava´úÂëʵÏÖµÄjavascript½âÊÍÆ÷£¬ËüʵÏÖÁËjavascriptµÄºËÐÄ£¬ÇкÏEcma-262³ß¶È£¬Ö§³Öjavascript³ß¶ÈµÄËùÓÐÌØÐÔ¡£ |
¸üÐÂʱ¼ä£º | 20201020 |
ʼþÃû³Æ£º | HTTP_JBossMQ_JMS_·´ÐòÁл¯Â©¶´[CVE-2017-7504][CNNVD-201705-937] |
Äþ¾²ÀàÐÍ£º | ÍøÂçͨѶ |
ʼþÃèÊö£º | Red Hat JBoss Application Server ÊÇÒ»¿î»ùÓÚJavaEEµÄ¿ªÔ´Ó¦Ó÷þÎñÆ÷¡£JBoss AS 4.x¼°Ö®Ç°°æ±¾ÖУ¬JbossMQʵÏÖ¹ý³ÌµÄJMS over HTTP Invocation LayerµÄHTTPServerILServlet.javaÎļþ´æÔÚ·´ÐòÁл¯Â©¶´£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖƵÄÐòÁл¯Êý¾ÝÀûÓø鶴ִÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20201020 |
ʼþÃû³Æ£º | TCP_ͨÓÃ_JavaRMI·´ÐòÁл¯_Ô¶³ÌÃüÁîÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃJavaRMI·´ÐòÁл¯Ô¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷µÄÐÐΪ£¬JavaRMI·´ÐòÁл¯Ô¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷µÄÐÐΪÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20201020 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | TCP_RDPÔ¶³Ì×ÀÃæµÇ¼_»á»°Á¬½Ó |
Äþ¾²ÀàÐÍ£º | Äþ¾²Éó¼Æ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·Ö÷»úÕýÔÚÏòÄ¿µÄIPµØÖ·Ö÷»úÔ¶³Ì×ÀÃæµÇ¼¿ÚÁî²Â½âµÄÐÐΪ¡£ Ô¶³Ì×ÀÃæÁ¬½Ó×é¼þÊÇ´ÓWindows 2000 Server¿ªÊ¼ÓÉ΢Èí¹«Ë¾ÌṩµÄ£¬ÔÚWINDOWS 2000 SERVERÖÐËû²»ÊÇĬÈÏ°²×°µÄ¡£¸Ã×é¼þÒ»¾ÍƳöÊܵ½Á˺ܶàÓû§µÄÓµ»¤ºÍϲºÃ£¬ËùÒÔÔÚWINDOWS WINDOWS2003¿ªÆôÒªÁìºÍXPÀàËÆ£¬Í¬Ñù¶Ô²Ù×÷²½Öè½øÐÐÁ˼ò»¯¡£ÒªÁìÈçÏ£º µÚÒ»²½£ºÔÚ×ÀÃæ¡°ÎҵĵçÄÔ¡±ÉϵãÊó±êÓÒ¼ü£¬Ñ¡Ôñ¡°ÊôÐÔ¡±¡£XPºÍ2003ÖÐ΢Èí¹«Ë¾½«¸Ã×é¼þµÄÆôÓÃÒªÁì½øÐÐÁ˸ïУ¬ÎÒÃÇͨ¹ý¼òµ¥µÄ¹´Ñ¡¾Í¿ÉÒÔÍê³ÉÔÚXPºÍ2003ÏÂÔ¶³Ì×ÀÃæÁ¬½Ó¹¦Ð§µÄ¿ªÆô¡£Èç¹ûÄ¿±êÖ÷»ú¿ªÆôÁËÔ¶³ÌÖն˷þÎñ£¬Ä¬È϶˿ÚÊÇ3389£¬¹¥»÷Õßͨ¹ý¶à´ÎʵÑéÓû§ÃûºÍÃÜÂëµÄ·½Ê½À´²Â½âÓû§¿ÚÁÈç¹û±»²ÂÖй¥»÷Õ߾ͿÉÒÔ»ñÇ¡µ±Ç°Óû§µÄËùÓÐȨÏÞ£¬½ø¶øÓÐÓпÉÄÜ»ñµÃ¹ÜÀíԱȨÏÞ¡£ µÚ¶þ²½£ºÔÚµ¯³öµÄϵͳÊôÐÔ´°¿ÚÖÐÑ¡Ôñ¡°Ô¶³Ì¡±±êÇ©¡£ µÚÈý²½£ºÔÚÔ¶³Ì±êÇ©ÖÐÕÒµ½¡°Ô¶³Ì×ÀÃ桱£¬ÔÚ¡°ÈÝÐíÓû§Á¬½Óµ½Õą̂¼ÆËã»ú¡±Ç°¶Ô¹´È¥µôºóÈ·¶¨¼´¿ÉÍê³ÉÔ¶³Ì×ÀÃæÁ¬½Ó¹¦Ð§µÄ¹Ø±Õ¡£ |
¸üÐÂʱ¼ä£º | 20201020 |
ʼþÃû³Æ£º | TCP_Oracle_WebLogic_·´ÐòÁл¯Â©¶´[CVE-2016-3510] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogic·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´£¬ÊÔͼͨ¹ý´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£ |
¸üÐÂʱ¼ä£º | 20201013 |