2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·£»£»£»£»Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©

Ðû²¼Ê±¼ä 2020-02-21

1.ÖйúÈËÃñÒøÐÐÐû²¼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶>ÐÐÒµ±ê×¼µÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬£¬£¬£¬ £¬£¬£¬Ðû²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·(JR/T 0068-2020)£¬£¬£¬£¬ £¬£¬£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄÌæ»»ÐÞ¶©°æ±¾¡£¡£¡£¡£¡£ÐÂ°æ¹æ·¶ÓÐÈý¸öÖØµãÐÞ¶©ÄÚÈÝ£º1¡¢Õë¶ÔÐÂÊÖÒÕ·ºÆðºÍÓ¦ÓÃÌá³öÁËеÄÇå¾²ÒªÇó£¨ÀýÈçÔöÌíÁËÐéÄ⻯¡¢ÔÆÅÌËãÇå¾²Ïà¹ØÒªÇ󣬣¬£¬£¬ £¬£¬£¬ÔöÌí¹úÃÜSMϵÁÐËã·¨Ïà¹ØµÄÇå¾²ÒªÇ󣬣¬£¬£¬ £¬£¬£¬ÔöÌí¶ÔÇå¾²µ¥Î»ºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅÇéÐÎÏà¹ØÒªÇ󣩣»£»£»£»2¡¢¾ÍеÄÓªÒµºÍî¿ÏµÒªÇó¾ÙÐÐÁËÔö²¹ºÍÃ÷È·£¨ÀýÈçÔöÌíÁËÌõÂëÖ§¸¶¡¢ÉúÒâÇå¾²ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÏà¹ØÒªÇ󣩣»£»£»£»3¡¢ÖØÐÂÊáÀí²¢ÌáÉý¹ØÓÚÓªÒµÒ»Á¬ÐÔÓëÔÖÄѻָ´¡¢Çå¾²ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄÇå¾²ÒªÇ󡣡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cebnet.com.cn/20200219/102639904.html


2.˼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷ÌØÈ¨ÕË»§ºÍ¾²Ì¬ÃÜÂ룬£¬£¬£¬ £¬£¬£¬½¨ÒéÁ¬Ã¦ÐÞ¸´


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆÐÞ¸´ÆäÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM£©ÖеÄÌØÈ¨ÕË»§¾²Ì¬ÃÜÂëÎó²î£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²î£¨CVE-2020-3158£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬ £¬£¬£¬Ëü¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÈ¨½Ï¸ßµÄÕÊ»§»á¼ûϵͳµÄÃô¸Ð²¿·Ö¡£¡£¡£¡£¡£Ë¼¿ÆÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬¡°¸ÃÎó²îÊÇÓÉÓÚijϵͳÕË»§¾ßÓÐĬÈϺ;²Ì¬ÃÜÂëÇÒ²¢²»ÊÜϵͳÖÎÀíÔ±¿ØÖƶøÔì³ÉµÄ¡£¡£¡£¡£¡£¡±SSM On-PremϵͳֻÓÐÔÚÆôÓÃÁ˸߿ÉÓÃÐÔ£¨HA£©¹¦Ð§Ê±²ÅÒ×Êܹ¥»÷£¬£¬£¬£¬ £¬£¬£¬µ«¸Ã¹¦Ð§Ä¬ÈÏδÆôÓᣡ£¡£¡£¡£Ë¼¿ÆÖÒÑԳƣ¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß²»ÐèÒªÓÐÓõĵǼ¾Í¿ÉÒÔÌᳫ¹¥»÷£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒ¿ÉÒÔʹÓøßÌØÈ¨Ä¬ÈÏÕÊ»§À´ÅþÁ¬Ò×Êܹ¥»÷µÄϵͳ£¬£¬£¬£¬ £¬£¬£¬»ñµÃ¶ÔϵͳÊý¾ÝµÄ¶Áд»á¼ûȨÏÞ£¬£¬£¬£¬ £¬£¬£¬²¢¸ü¸ÄÆäÉèÖᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-critical-bug-static-password-in-smart-software-manager-patch-now-says-cisco/


3.AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´Á½¸ö´úÂëÖ´ÐÐÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеÄÁ½¸ö´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£µÚÒ»¸öÎó²î£¨CVE-2020-3764£©Êǿɵ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÔ½½çдÎó²î£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe Media Encoder 14.0¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2020-3765£©Ò²ÊÇÓÉÔ½½çдµ¼ÖµĴúÂëÖ´ÐÐÎó²î£¬£¬£¬£¬ £¬£¬£¬µ«¹¥»÷Ö»ÄÜÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖоÙÐУ¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe After Effects°æ±¾16.1.2¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-releases-out-of-schedule-fixes-for-critical-vulnerabilities/


4.Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Apache TomcatЧÀÍÆ÷±£´æÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¶ÁÈ¡»ò°üÀ¨TomcatÉÏËùÓÐwebappĿ¼ÏµÄí§ÒâÎļþ£¬£¬£¬£¬ £¬£¬£¬È磺webappÉèÖÃÎļþ»òÔ´´úÂëµÈ¡£¡£¡£¡£¡£¸ÃÎó²îÓëTomcat AJPЭÒéÓйØ£¬£¬£¬£¬ £¬£¬£¬Tomcat AJP ConnectorĬÈÏÉèÖÃϼ´Îª¿ªÆô״̬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËTomcat 6/7/8/9È«°æ±¾£¬£¬£¬£¬ £¬£¬£¬Apache¹Ù·½ÒÑÐû²¼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´ËÎó²î¾ÙÐÐÐÞ¸´£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§ÏÂÔØÊ¹Óᣡ£¡£¡£¡£ÓÉÓÚTomcat 6ÒѾ­×èֹά»¤£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâÊܹ¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487


5.ÃÀ¹ú²ÎÒéÔ±Ìá³öÐÂÊý¾Ý±£»£»£»£»¤·¨°¸£¬£¬£¬£¬ £¬£¬£¬½¨Ò齨ÉèÊý¾Ý±£»£»£»£»¤¾Ö


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úŦԼÖݲÎÒéÔ±¼ª¶û˹²¼À¼µÂ£¨Kirsten Gillibrand£©ÉÏÖÜÐû²¼ÁËÒ»ÏîÁ¢·¨²Ý°¸£¬£¬£¬£¬ £¬£¬£¬¸Ã·¨°¸½«½¨ÉèÒ»¸ö×ÔÁ¦µÄÁª°î»ú¹¹£¬£¬£¬£¬ £¬£¬£¬¼´Êý¾Ý±£»£»£»£»¤¾Ö£¬£¬£¬£¬ £¬£¬£¬Ö¼ÔÚ½ç˵¡¢ÖٲúÍÖ´ÐÐÊý¾Ý±£»£»£»£»¤¹æÔò¡£¡£¡£¡£¡£Õâλ²ÎÒéÔ±ÒÔΪ£¬£¬£¬£¬ £¬£¬£¬¡¶Áª°îÉÌҵίԱ»á·¨¡·²¢Î´½â¾öÊý¾Ý±£»£»£»£»¤·½ÃæµÄÌôÕ½£¬£¬£¬£¬ £¬£¬£¬¶øÃÀ¹úÔÚÓ¦¶ÔÊý¾Ý±£»£»£»£»¤ÌôÕ½ºÍÊý×Öʱ´úµÄÐí¶àÆäËüÌôÕ½·½ÃæÂäÎ飬£¬£¬£¬ £¬£¬£¬ÃÀ¹úҲûÓÐÒ»¸öרÃŵĻú¹¹À´Ö´ÐÐÊý¾ÝÒþ˽¹æÔò¡£¡£¡£¡£¡£ÈôÊǸ÷¨°¸»ñµÃͨ¹ý£¬£¬£¬£¬ £¬£¬£¬½«ÊÊÓÃÓÚÈκÎÊÕÈëÁè¼Ý2500ÍòÃÀÔª£¬£¬£¬£¬ £¬£¬£¬»òÖÎÀí5Íò»ò¸ü¶àÈ˵ÄСÎÒ˽¼ÒÊý¾ÝµÄ¹«Ë¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/us-senator-proposes-new-data-protection-bill-37232e0b


6.¸çÂ×±ÈÑÇCommunity CareÔâÀÕË÷¹¥»÷£¬£¬£¬£¬ £¬£¬£¬»¼ÕßÊý¾Ý¿ÉÄÜй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¸çÂ×±ÈÑÇÊ×¶¼µØÇø×î´óµÄ×ÔÁ¦Ò½ÁÆ»ú¹¹Community Care»¼ÕßÊý¾Ý¿ÉÄÜй¶£¬£¬£¬£¬ £¬£¬£¬¸ÃÊÂÎñÊÇÓÉÆä»á¼ÆÊ¦ÊÂÎñËùBSTÔâµ½ÀÕË÷Èí¼þ¹¥»÷µ¼ÖµÄ¡£¡£¡£¡£¡£BSTÓÚ2019Äê12ÔÂ7ÈÕ·¢Ã÷°üÀ¨¿Í»§»á¼ÆºÍ˰ÊÕÊý¾ÝÔÚÄڵIJ¿·ÖÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬£¬£¬£¬ £¬£¬£¬µ«¸Ã¹«Ë¾Äܹ»Ê¹Óñ¸·Ý»¹Ô­Îļþ¡£¡£¡£¡£¡£ÔÚÖ®ºóµÄÊÓ²ìÖУ¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÓÚ2ÔÂ5ÈÕÈ·Èϲ¿·Ö»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶£¬£¬£¬£¬ £¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÉúÈÕ¡¢ÌõÄ¿ºÅÂëºÍÕʵ¥´úÂ룬£¬£¬£¬ £¬£¬£¬µ«²»°üÀ¨ÒøÐÐÕʺš¢Éç»áÇå¾²ºÅÂëºÍ²¡ÀúÐÅÏ¢¡£¡£¡£¡£¡£BST»òCommunity Care¶¼Ã»ÓÐ͸¶ÊÜÓ°ÏìµÄ»¼ÕßÈËÊý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://dailygazette.com/article/2020/02/19/data-breach-community-Care-physicians