2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡· £»£»£»£»£»£»Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©

°ä²¼¹¦·ò 2020-02-21

1.ÖйúÈËÃñÒøÐа䲼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶>ÐÐÒµ³ß¶ÈµÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£© £¬£¬£¬£¬£¬£¬°ä²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·(JR/T 0068-2020) £¬£¬£¬£¬£¬£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄ´úÌæ¶©Õý°æ±¾¡£¡£¡£¡£¡£ÐÂ°æ¹æ·¶ÓÐÈý¸ö³Áµã¶©ÕýÄÚÈÝ£º1¡¢Õë¶Ôм¼Êõ³öÏÖºÍÀûÓÃÌá³öÁËÐµİ²È«ÒªÇó£¨ÀýÈçÔö³¤ÁËÐé¹¹»¯¡¢ÔÆÍÆË㰲ȫÓйØÒªÇó £¬£¬£¬£¬£¬£¬Ôö³¤¹úÃÜSMϵÁÐËã·¨ÓйصݲȫҪÇó £¬£¬£¬£¬£¬£¬Ôö³¤¶Ô°²È«µ¥ÔªºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅ»·¾³ÓйØÒªÇó£© £»£»£»£»£»£»2¡¢¾ÍеÄÒµÎñºÍ¼à¹ÜÒªÇó½øÐÐÁ˲¹³äºÍÃ÷È·£¨ÀýÈçÔö³¤ÁËÌõÂëÖ§¸¶¡¢ÂòÂô°²È«ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÓйØÒªÇó£© £»£»£»£»£»£»3¡¢³ÁÐÂÊáÀí²¢ÌáÉý¹ØÓÚÒµÎñÂ½ÐøÐÔÓë¿àÄѸ´Ô­¡¢°²È«ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄ°²È«ÒªÇ󡣡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cebnet.com.cn/20200219/102639904.html


2.˼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷ÌØÈ¨ÕË»§ºÍ¾²Ì¬ÃÜÂë £¬£¬£¬£¬£¬£¬½¨ÒéÁ¢¿Ì½¨¸´


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


˼¿Æ½¨¸´ÆäÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM£©ÖеÄÌØÈ¨ÕË»§¾²Ì¬ÃÜÂë·ì϶ £¬£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2020-3158£©µÄCVSSÆÀ·ÖΪ9.8·Ö £¬£¬£¬£¬£¬£¬Ëü¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÈ¨½Ï¸ßµÄÕÊ»§½Ó¼ûϵͳµÄÃô¸Ð²¿ÃÅ¡£¡£¡£¡£¡£Ë¼¿Æ°µÊ¾ £¬£¬£¬£¬£¬£¬¡°¸Ã·ì϶ÊÇÓÉÓÚijϵͳÕË»§ÓµÓÐĬÈϺ;²Ì¬ÃÜÂëÇÒ²¢²»ÊÜϵͳÖÎÀíÔ±½ÚÔì¶øÔì³ÉµÄ¡£¡£¡£¡£¡£¡±SSM On-PremϵͳֻÓÐÔÚÆôÓÃÁ˸߿ÉÓÃÐÔ£¨HA£©Ö°ÄÜʱ²ÅÒ×Êܹ¥»÷ £¬£¬£¬£¬£¬£¬µ«¸ÃÖ°ÄÜĬÈÏδÆôÓᣡ£¡£¡£¡£Ë¼¿ÆÖÒ¸æ³Æ £¬£¬£¬£¬£¬£¬¹¥»÷Õß²»±ØÒªÓÐЧµÄµÇ¼¾ÍÄܹ»ÌáÒé¹¥»÷ £¬£¬£¬£¬£¬£¬²¢ÇÒÄܹ»Ê¹ÓøßÌØÈ¨Ä¬ÈÏÕÊ»§À´ÏνÓÒ×Êܹ¥»÷µÄϵͳ £¬£¬£¬£¬£¬£¬»ñµÃ¶ÔϵͳÊý¾ÝµÄ¶Áд½Ó¼ûȨÏÞ £¬£¬£¬£¬£¬£¬²¢¸ü¸ÄÆäÉèÖᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-critical-bug-static-password-in-smart-software-manager-patch-now-says-cisco/


3.Adobe°ä²¼´¹Î£°²È«¸üР£¬£¬£¬£¬£¬£¬½¨¸´Á½¸ö´úÂëÖ´Ðзì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Adobe°ä²¼´¹Î£°²È«¸üР£¬£¬£¬£¬£¬£¬½¨¸´Æä²úÆ·ÖеÄÁ½¸ö´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶£¨CVE-2020-3764£©Êǿɵ¼ÖÂËÁÒâ´úÂëÖ´ÐеÄÔ½½çд·ì϶ £¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËWindowsƽ̨ÉϵÄAdobe Media Encoder 14.0¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶£¨CVE-2020-3765£©Ò²ÊÇÓÉÔ½½çдµ¼ÖµĴúÂëÖ´Ðзì϶ £¬£¬£¬£¬£¬£¬µ«¹¥»÷Ö»ÄÜÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖнøÐÐ £¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËWindowsƽ̨ÉϵÄAdobe After Effects°æ±¾16.1.2¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-releases-out-of-schedule-fixes-for-critical-vulnerabilities/


4.Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Apache Tomcat·þÎñÆ÷´æÔÚÎļþÔ̺¬·ì϶£¨CVE-2020-1938£© £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶¶ÁÈ¡»òÔ̺¬TomcatÉÏËùÓÐwebappĿ¼ÏµÄËÁÒâÎļþ £¬£¬£¬£¬£¬£¬È磺webappÅäÖÃÎļþ»òÔ´´úÂëµÈ¡£¡£¡£¡£¡£¸Ã·ì϶ÓëTomcat AJPºÍ̸ÓÐ¹Ø £¬£¬£¬£¬£¬£¬Tomcat AJP ConnectorĬÈÏÅäÖÃϼ´Îª¿ªÆô״̬ £¬£¬£¬£¬£¬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËTomcat 6/7/8/9È«°æ±¾ £¬£¬£¬£¬£¬£¬Apache¹Ù·½ÒѰ䲼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´Ë·ì϶½øÐн¨¸´ £¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÏÂÔØÊ¹Óᣡ£¡£¡£¡£ÓÉÓÚTomcat 6ÒѾ­ÖÕ³¡ÊØ»¤ £¬£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâ·ê¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487


5.ÃÀ¹ú²ÎÒéÔ±Ìá³öÐÂÊý¾Ý± £»£»£»£»£»£»¤·¨°¸ £¬£¬£¬£¬£¬£¬½¨Òé³ÉÁ¢Êý¾Ý± £»£»£»£»£»£»¤¾Ö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úŦԼÖݲÎÒéÔ±¼ª¶û˹²¼À¼µÂ£¨Kirsten Gillibrand£©ÉÏÖܰ䲼ÁËÒ»ÏîÁ¢·¨²Ý°¸ £¬£¬£¬£¬£¬£¬¸Ã·¨°¸½«³ÉÁ¢Ò»¸ö¶ÀÁ¢µÄÁª¹ú»ú¹¹ £¬£¬£¬£¬£¬£¬¼´Êý¾Ý± £»£»£»£»£»£»¤¾Ö £¬£¬£¬£¬£¬£¬Ö¼ÔÚ½ç˵¡¢ÖٲúÍÖ´ÐÐÊý¾Ý± £»£»£»£»£»£»¤¹æ¶¨¡£¡£¡£¡£¡£Õâλ²ÎÒéÔ±ÒÔΪ £¬£¬£¬£¬£¬£¬¡¶Áª¹úÒµÎñίԱ»á·¨¡·²¢Î´½â¾öÊý¾Ý± £»£»£»£»£»£»¤·½ÃæµÄÌôÕ½ £¬£¬£¬£¬£¬£¬¶øÃÀ¹úÔÚÓ¦¶ÔÊý¾Ý± £»£»£»£»£»£»¤ÌôÕ½ºÍÊý×ÖʱÆÚµÄºÜ¶àÆäËüÌôÕ½·½ÃæÂäºó £¬£¬£¬£¬£¬£¬ÃÀ¹úҲûÓÐÒ»¸öרÃŵĻú¹¹À´Ö´ÐÐÊý¾ÝÒþÖԹ涨¡£¡£¡£¡£¡£ÈôÊǸ÷¨°¸»ñµÃͨ¹ý £¬£¬£¬£¬£¬£¬½«ºÏÓÃÓÚÈκÎÊÕÈ볬¹ý2500ÍòÃÀÔª £¬£¬£¬£¬£¬£¬»òÖÎÀí5Íò»ò¸ü¶àÈ˵ÄÓ×ÎÒÊý¾ÝµÄ¹«Ë¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/us-senator-proposes-new-data-protection-bill-37232e0b


6.¸çÂ×±ÈÑÇCommunity CareÔâÀÕË÷¹¥»÷ £¬£¬£¬£¬£¬£¬»¼ÕßÊý¾Ý¿ÉÄÜй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¸çÂ×±ÈÑÇÊ×¶¼µØÓò×î´óµÄ¶ÀÁ¢Ò½ÁÆ»ú¹¹Community Care»¼ÕßÊý¾Ý¿ÉÄÜй¶ £¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÊÇÓÉÆä¹ÜÕÊʦÊÂÎñËùBSTÔâµ½ÀÕË÷Èí¼þ¹¥»÷µ¼Öµġ£¡£¡£¡£¡£BSTÓÚ2019Äê12ÔÂ7ÈÕ·¢ÏÖÔ̺¬¿Í»§¹ÜÕʺÍ˰ÊÕÊý¾ÝÔÚÄڵIJ¿ÃÅÍøÂçϰȾÁËÀÕË÷²¡¶¾ £¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾¿ÉÄÜʹÓñ¸·Ý»¹Ô­Îļþ¡£¡£¡£¡£¡£ÔÚÖ®ºóµÄµ÷²éÖÐ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ2ÔÂ5ÈÕÈ·Èϲ¿ÃÅ»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶ £¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢Ìõ¿îºÅÂëºÍÕʵ¥´úÂë £¬£¬£¬£¬£¬£¬µ«²»Ô̺¬ÒøÐÐÕʺš¢Éç»á°²È«ºÅÂëºÍ²¡ÀúÐÅÏ¢¡£¡£¡£¡£¡£BST»òCommunity Care¶¼Ã»ÓÐй©ÊÜÓ°ÏìµÄ»¼ÕßÈËÊý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://dailygazette.com/article/2020/02/19/data-breach-community-Care-physicians