Oracle¶à¸ö²úÆ·Çå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-07-15

0x00 Îó²î¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

WebLogic

CVE-2020-14625

ÑÏÖØ

ÊÇ

WebLogic 12.2.1.3.0

WebLogic 12.2.1.4.0

WebLogic 14.1.1.0.0

CVE-2020-14644

ÑÏÖØ

ÊÇ

CVE-2020-14687

ÑÏÖØ

ÊÇ

CVE-2020-14645

ÑÏÖØ

ÊÇ

WebLogic 10.3.6.0.0

WebLogic 12.1.3.0.0

WebLogic 12.2.1.3.0

WebLogic 12.2.1.4.0

WebLogic 14.1.1.0.0

Oracle SD-WAN Aware

CVE-2020-14701

ÑÏÖØ

ÊÇ

Oracle SD-WAN Aware 8.2

Oracle SD-WAN Edge

CVE-2020-14606

ÑÏÖØ

ÊÇ

Oracle SD-WAN Edge 8.2,9.0



0x01 Îó²îÏêÇé


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


2020Äê7ÔÂ14ÈÕ£¬£¬£¬ £¬£¬£¬Oracle¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬ £¬£¬£¬ÐÞ¸´ÁË433¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬Éæ¼°ÁËOracle Weblogic¡¢Oracle CoherenceµÈ¶à¿î²úÆ·¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨ËĸöÆÀ·ÖΪ9.8µÄOracle WebLogic Server·´ÐòÁл¯Îó²î£¨CVE-2020-14625¡¢CVE-2020-14644¡¢CVE-2020-14645 ¡¢CVE-2020-14687£©£¬£¬£¬ £¬£¬£¬Á½¸öÆÀ·ÖΪ10µÄOracle Communications ApplicationsÇå¾²Îó²î£¨CVE-2020-14701¡¢CVE-2020-14606£©¡£¡£¡£¡£¡£¡£

Oracle WebLogic Server·´ÐòÁл¯Îó²î

ÕâËĸöÎó²îµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýIIOP¡¢T3ЭÒé·¢ËͶñÒâÇëÇ󣬣¬£¬ £¬£¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£

Oracle Communications ApplicationsÇå¾²Îó²î

ÕâÁ½¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpujul2020.html

WeblogicÔÝʱÐÞ²¹½¨Ò飺

1. ÈôÊDz»ÒÀÀµT3ЭÒé¾ÙÐÐJVMͨѶ£¬£¬£¬ £¬£¬£¬½ûÓÃT3ЭÒé¡£¡£¡£¡£¡£¡£

? ½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬ £¬£¬£¬ÔÚbase_domainÉèÖÃÒ³ÃæÖУ¬£¬£¬ £¬£¬£¬½øÈëÇ徲ѡÏî¿¨Ò³Ãæ£¬£¬£¬ £¬£¬£¬µã»÷ɸѡÆ÷£¬£¬£¬ £¬£¬£¬ÉèÖÃɸѡÆ÷£»£»£»£»£»£»£»

? ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬ £¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔò¿òÖÐÊäÈë 7001 deny t3 t3sÉúÑÄÉúЧ£»£»£»£»£»£»£»

? ÖØÆôWeblogicÏîÄ¿£¬£¬£¬ £¬£¬£¬Ê¹ÉèÖÃÉúЧ¡£¡£¡£¡£¡£¡£

2. ÈôÊDz»ÒÀÀµIIOPЭÒé¾ÙÐÐJVMͨѶ£¬£¬£¬ £¬£¬£¬½ûÓÃIIOPЭÒé¡£¡£¡£¡£¡£¡£

? ½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬ £¬£¬£¬ÔÚbase_domainÉèÖÃÒ³ÃæÖУ¬£¬£¬ £¬£¬£¬½øÈëÇ徲ѡÏî¿¨Ò³Ãæ£»£»£»£»£»£»£»

? Ñ¡Ôñ¡°Ð§ÀÍ¡±->¡±AdminServer¡±->¡±Ð­Ò顱£¬£¬£¬ £¬£¬£¬×÷·Ï¡°ÆôÓÃIIOP¡±µÄ¹´Ñ¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»

? ÖØÆôWeblogicÏîÄ¿£¬£¬£¬ £¬£¬£¬Ê¹ÉèÖÃÉúЧ¡£¡£¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


0x04 ²Î¿¼Á´½Ó


https://www.oracle.com/security-alerts/cpujul2020.html


0x05 ʱ¼äÏß


2020-07-14 Oracle¹Ù·½Ðû²¼Ç徲ͨ¸æ

2020-07-15 VSRCÐû²¼Îó²îͨ¸æ



ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾