¡¾Ô­´´Îó²î¡¿WebLogic Blind XXEÎó²îͨ¸æ£¨CVE-2020-14820£©

Ðû²¼Ê±¼ä 2020-10-22

Îó²î¸ÅÊö

 

Oracle¹Ù·½Ðû²¼ÁË10Ô·ݵÄÇå¾²²¹¶¡, ²¹¶¡ÖаüÀ¨ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÎó²î £¬Îó²î±àºÅΪCVE-2020-14820¡£Í¨¹ý¸ÃÎó²î £¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3»òIIOPЭÒéÖÐ £¬Í¨¹ý¶ÔЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯ £¬´Ó¶øʵÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£


Îó²îʱ¼äÖá


2020Äê5ÔÂ11ÈÕ £¬ADLab½«Îó²îÏêÇéÌá½»¸øOracle¹Ù·½£»

2020Äê5ÔÂ12ÈÕ £¬Oracle¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´£»

2020Äê10ÔÂ21ÈÕ £¬Oracle¹Ù·½Ðû²¼Çå¾²²¹¶¡¡£


ÊÜÓ°Ïì°æ±¾ 


Weblogic 10.3.6.0.0

Weblogic 12.1.3.0.0

Weblogic 12.2.1.3.0

Weblogic 12.2.1.4.0

Weblogic 14.1.1.0.0


1.png


Îó²îʹÓà


²âÊÔÇéÐΣºWebLogicServer 10.3.6.0.0

Îó²îʹÓÃЧ¹û£º



2.png


¹æ±Ü¼Æ»® 


1¡¢Éý¼¶²¹¶¡

https://www.oracle.com/security-alerts/cpuoct2020.html


2¡¢¿ØÖÆT3ЭÒéµÄ»á¼û


Ïêϸ²Ù×÷£º

1£©½øÈëWebLogic¿ØÖÆ̨ £¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖÐ £¬½øÈë¡°Çå¾²¡±Ñ¡ÏҳÃæ £¬µã»÷¡°É¸Ñ¡Æ÷¡± £¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖá£

2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl £¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s £¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£

3£©ÉúÑĺóÐèÖØÐÂÆô¶¯ £¬¹æÔò·½¿ÉÉúЧ¡£


3.png


3¡¢Õ¥È¡ÆôÓÃIIOPЭÒé


ÉÏ°¶WebLogic¿ØÖÆ̨ £¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer


4.png


ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


DLab½¨ÉèÓÚ1999Äê £¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò» £¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ £¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î½ü1100¸ö £¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î900Óà¸ö £¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØϵͳÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£


5.jpg