2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·£»£»£»£»£»Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©

Ðû²¼Ê±¼ä 2020-02-21

1.ÖйúÈËÃñÒøÐÐÐû²¼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶>ÐÐÒµ±ê×¼µÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬£¬£¬£¬£¬Ðû²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·(JR/T 0068-2020)£¬£¬£¬£¬£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄÌæ»»ÐÞ¶©°æ±¾¡£¡£¡£¡£¡£¡£¡£ÐÂ°æ¹æ·¶ÓÐÈý¸öÖØµãÐÞ¶©ÄÚÈÝ£º1¡¢Õë¶ÔÐÂÊÖÒÕ·ºÆðºÍÓ¦ÓÃÌá³öÁËеÄÇå¾²ÒªÇó£¨ÀýÈçÔöÌíÁËÐéÄ⻯¡¢ÔÆÅÌËãÇå¾²Ïà¹ØÒªÇ󣬣¬£¬£¬£¬ÔöÌí¹úÃÜSMϵÁÐËã·¨Ïà¹ØµÄÇå¾²ÒªÇ󣬣¬£¬£¬£¬ÔöÌí¶ÔÇå¾²µ¥Î»ºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅÇéÐÎÏà¹ØÒªÇ󣩣»£»£»£»£»2¡¢¾ÍеÄÓªÒµºÍî¿ÏµÒªÇó¾ÙÐÐÁËÔö²¹ºÍÃ÷È·£¨ÀýÈçÔöÌíÁËÌõÂëÖ§¸¶¡¢ÉúÒâÇå¾²ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÏà¹ØÒªÇ󣩣»£»£»£»£»3¡¢ÖØÐÂÊáÀí²¢ÌáÉý¹ØÓÚÓªÒµÒ»Á¬ÐÔÓëÔÖÄѻָ´¡¢Çå¾²ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄÇå¾²ÒªÇ󡣡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cebnet.com.cn/20200219/102639904.html


2.˼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷ÌØÈ¨ÕË»§ºÍ¾²Ì¬ÃÜÂ룬£¬£¬£¬£¬½¨ÒéÁ¬Ã¦ÐÞ¸´


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆÐÞ¸´ÆäÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM£©ÖеÄÌØÈ¨ÕË»§¾²Ì¬ÃÜÂëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2020-3158£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬Ëü¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÈ¨½Ï¸ßµÄÕÊ»§»á¼ûϵͳµÄÃô¸Ð²¿·Ö¡£¡£¡£¡£¡£¡£¡£Ë¼¿ÆÌåÏÖ£¬£¬£¬£¬£¬¡°¸ÃÎó²îÊÇÓÉÓÚijϵͳÕË»§¾ßÓÐĬÈϺ;²Ì¬ÃÜÂëÇÒ²¢²»ÊÜϵͳÖÎÀíÔ±¿ØÖƶøÔì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£¡±SSM On-PremϵͳֻÓÐÔÚÆôÓÃÁ˸߿ÉÓÃÐÔ£¨HA£©¹¦Ð§Ê±²ÅÒ×Êܹ¥»÷£¬£¬£¬£¬£¬µ«¸Ã¹¦Ð§Ä¬ÈÏδÆôÓᣡ£¡£¡£¡£¡£¡£Ë¼¿ÆÖÒÑԳƣ¬£¬£¬£¬£¬¹¥»÷Õß²»ÐèÒªÓÐÓõĵǼ¾Í¿ÉÒÔÌᳫ¹¥»÷£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔʹÓøßÌØÈ¨Ä¬ÈÏÕÊ»§À´ÅþÁ¬Ò×Êܹ¥»÷µÄϵͳ£¬£¬£¬£¬£¬»ñµÃ¶ÔϵͳÊý¾ÝµÄ¶Áд»á¼ûȨÏÞ£¬£¬£¬£¬£¬²¢¸ü¸ÄÆäÉèÖᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-critical-bug-static-password-in-smart-software-manager-patch-now-says-cisco/


3.AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Á½¸ö´úÂëÖ´ÐÐÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеÄÁ½¸ö´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²î£¨CVE-2020-3764£©Êǿɵ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÔ½½çдÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe Media Encoder 14.0¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2020-3765£©Ò²ÊÇÓÉÔ½½çдµ¼ÖµĴúÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬µ«¹¥»÷Ö»ÄÜÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖоÙÐУ¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe After Effects°æ±¾16.1.2¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-releases-out-of-schedule-fixes-for-critical-vulnerabilities/


4.Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Apache TomcatЧÀÍÆ÷±£´æÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¶ÁÈ¡»ò°üÀ¨TomcatÉÏËùÓÐwebappĿ¼ÏµÄí§ÒâÎļþ£¬£¬£¬£¬£¬È磺webappÉèÖÃÎļþ»òÔ´´úÂëµÈ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓëTomcat AJPЭÒéÓйØ£¬£¬£¬£¬£¬Tomcat AJP ConnectorĬÈÏÉèÖÃϼ´Îª¿ªÆô״̬£¬£¬£¬£¬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËTomcat 6/7/8/9È«°æ±¾£¬£¬£¬£¬£¬Apache¹Ù·½ÒÑÐû²¼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´ËÎó²î¾ÙÐÐÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÓû§ÏÂÔØÊ¹Óᣡ£¡£¡£¡£¡£¡£ÓÉÓÚTomcat 6ÒѾ­×èֹά»¤£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâÊܹ¥»÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487


5.ÃÀ¹ú²ÎÒéÔ±Ìá³öÐÂÊý¾Ý±£»£»£»£»£»¤·¨°¸£¬£¬£¬£¬£¬½¨Ò齨ÉèÊý¾Ý±£»£»£»£»£»¤¾Ö


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úŦԼÖݲÎÒéÔ±¼ª¶û˹²¼À¼µÂ£¨Kirsten Gillibrand£©ÉÏÖÜÐû²¼ÁËÒ»ÏîÁ¢·¨²Ý°¸£¬£¬£¬£¬£¬¸Ã·¨°¸½«½¨ÉèÒ»¸ö×ÔÁ¦µÄÁª°î»ú¹¹£¬£¬£¬£¬£¬¼´Êý¾Ý±£»£»£»£»£»¤¾Ö£¬£¬£¬£¬£¬Ö¼ÔÚ½ç˵¡¢ÖٲúÍÖ´ÐÐÊý¾Ý±£»£»£»£»£»¤¹æÔò¡£¡£¡£¡£¡£¡£¡£Õâλ²ÎÒéÔ±ÒÔΪ£¬£¬£¬£¬£¬¡¶Áª°îÉÌҵίԱ»á·¨¡·²¢Î´½â¾öÊý¾Ý±£»£»£»£»£»¤·½ÃæµÄÌôÕ½£¬£¬£¬£¬£¬¶øÃÀ¹úÔÚÓ¦¶ÔÊý¾Ý±£»£»£»£»£»¤ÌôÕ½ºÍÊý×Öʱ´úµÄÐí¶àÆäËüÌôÕ½·½ÃæÂäÎ飬£¬£¬£¬£¬ÃÀ¹úҲûÓÐÒ»¸öרÃŵĻú¹¹À´Ö´ÐÐÊý¾ÝÒþ˽¹æÔò¡£¡£¡£¡£¡£¡£¡£ÈôÊǸ÷¨°¸»ñµÃͨ¹ý£¬£¬£¬£¬£¬½«ÊÊÓÃÓÚÈκÎÊÕÈëÁè¼Ý2500ÍòÃÀÔª£¬£¬£¬£¬£¬»òÖÎÀí5Íò»ò¸ü¶àÈ˵ÄСÎÒ˽¼ÒÊý¾ÝµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/us-senator-proposes-new-data-protection-bill-37232e0b


6.¸çÂ×±ÈÑÇCommunity CareÔâÀÕË÷¹¥»÷£¬£¬£¬£¬£¬»¼ÕßÊý¾Ý¿ÉÄÜй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¸çÂ×±ÈÑÇÊ×¶¼µØÇø×î´óµÄ×ÔÁ¦Ò½ÁÆ»ú¹¹Community Care»¼ÕßÊý¾Ý¿ÉÄÜй¶£¬£¬£¬£¬£¬¸ÃÊÂÎñÊÇÓÉÆä»á¼ÆÊ¦ÊÂÎñËùBSTÔâµ½ÀÕË÷Èí¼þ¹¥»÷µ¼ÖµÄ¡£¡£¡£¡£¡£¡£¡£BSTÓÚ2019Äê12ÔÂ7ÈÕ·¢Ã÷°üÀ¨¿Í»§»á¼ÆºÍ˰ÊÕÊý¾ÝÔÚÄڵIJ¿·ÖÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Äܹ»Ê¹Óñ¸·Ý»¹Ô­Îļþ¡£¡£¡£¡£¡£¡£¡£ÔÚÖ®ºóµÄÊÓ²ìÖУ¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ2ÔÂ5ÈÕÈ·Èϲ¿·Ö»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÉúÈÕ¡¢ÌõÄ¿ºÅÂëºÍÕʵ¥´úÂ룬£¬£¬£¬£¬µ«²»°üÀ¨ÒøÐÐÕʺš¢Éç»áÇå¾²ºÅÂëºÍ²¡ÀúÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£BST»òCommunity Care¶¼Ã»ÓÐ͸¶ÊÜÓ°ÏìµÄ»¼ÕßÈËÊý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://dailygazette.com/article/2020/02/19/data-breach-community-Care-physicians