¡¾Ô­´´·ì϶¡¿Oracle WebLogic Ô¶³ÌºÅÁîÖ´Ðзì϶£¨¼´CVE-2019-2725²¹¶¡Èƹý£©

°ä²¼¹¦·ò 2019-06-17
0x01 ·ìϼûèÊö


2019Äê4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬Oracle¹Ù·½°ä²¼ÁËWebLogic wls9-async¼°wls-wsat×é¼þÔ¶³ÌºÅÁîÖ´Ðзì϶µÄ²¹¶¡£¡£¡£¡£¡£¡£¡£¨CVE-2019-2725£©£¬£¬£¬£¬£¬£¬https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅADLabµÚÒ»¹¦·ò¶Ô¸Ã²¹¶¡½øÐÐÁËÉî¿Ì×êÑУ¬£¬£¬£¬£¬£¬·¢Ïָò¹¶¡´æÔÚ°²È«È±µã£¬£¬£¬£¬£¬£¬ÔڵͰ汾JDKµÄ»·¾³ÖÐÄܹ»±»Èƹýµ¼ÖÂËÁÒâÔ¶³ÌºÅÁîÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£ADLabÒÑÏòOracle¹Ù·½·´À¡ÁËCVE-2019-2725²¹¶¡ÈƹýµÄ·ì϶£¬£¬£¬£¬£¬£¬²¢µÃµ½Á˹ٷ½¼òÖ±ÈÏ¡£¡£¡£¡£¡£¡£¡£ÓÉÓڸ÷ì϶ÄÜʹ¹¥»÷ÕßÔ¶³ÌÖ´ÐÐËÁÒâºÅÁ£¬£¬£¬£¬£¬Ä¿Ç°¹Ù·½²¹¶¡ÉÐδ°ä²¼ÇÒÒÑÓÐЧ»§Êܵ½ÒÉËÆ¸Ã·ì϶µÄ¹¥»÷£¬£¬£¬£¬£¬£¬½¨ÒéËùÓÐʹÓÃOracle WebLogicµÄÓû§¾¡¿ì×Ô¶¯²¿ÊðÏàÓ¦·À»¤¡£¡£¡£¡£¡£¡£¡£


0x02 ·ì϶¹¦·òÖá


2019Äê6ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ADLab½«·ì϶ÏêÇéÌá½»¸øOracle¹Ù·½£»£»£»£»£»£»£»£»


2019Äê6ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Oracle¹Ù·½È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·½¨¸´¡£¡£¡£¡£¡£¡£¡£


0x03 Ó°Ïì°æ±¾


Oracle WebLogic Server 10.3.6.0


0x04 ·ì϶ÀûÓÃ


²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0 + CVE-2019-2725²¹¶¡


ÀûÓùý³Ì£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



0x05 һʱ½â¾ö¹æ»®


¹Ù·½²¹¶¡Ç°µÄһʱ·À»¤£º


ɾ³ýwls9_async_response.war¡¢wls_wsat.war¼°ÓйØÎļþ¼Ð£¬£¬£¬£¬£¬£¬²¢³ÁÆôweblogic·þÎñ¡£¡£¡£¡£¡£¡£¡£


²»ÈÝ_async/*¼°wls-wsat/*´ó¾ÖµÄURLõè¾¶½Ó¼û¡£¡£¡£¡£¡£¡£¡£


ʹÓÃ1.7¼°ÒÔÉϵÄjava°æ±¾ÔËÐÐWebLogic£¨Õë¶ÔĿǰÁ÷´«µÄµÍ°æ±¾JDKÀûÓã©¡£¡£¡£¡£¡£¡£¡£