¡¾Ô´´Îó²î¡¿Oracle WebLogic Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨¼´CVE-2019-2725²¹¶¡Èƹý£©
Ðû²¼Ê±¼ä 2019-06-172019Äê4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬Oracle¹Ù·½Ðû²¼ÁËWebLogic wls9-async¼°wls-wsat×é¼þÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄ²¹¶¡£¡£¡£¡£¡£¡£¡£¨CVE-2019-2725£©£¬£¬£¬£¬£¬£¬£¬https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html¡£¡£¡£¡£¡£¡£¡£
0x02 Îó²îʱ¼äÖá
2019Äê6ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬ADLab½«Îó²îÏêÇéÌá½»¸øOracle¹Ù·½£»£»£»
0x03 Ó°Ïì°æ±¾
Oracle WebLogic Server 10.3.6.0
0x04 Îó²îʹÓÃ
²âÊÔÇéÐΣºWebLogic Server 10.3.6.0 + CVE-2019-2725²¹¶¡

¹Ù·½²¹¶¡Ç°µÄÔÝʱ·À»¤£º
ɾ³ýwls9_async_response.war¡¢wls_wsat.war¼°Ïà¹ØÎļþ¼Ð£¬£¬£¬£¬£¬£¬£¬²¢ÖØÆôweblogicЧÀÍ¡£¡£¡£¡£¡£¡£¡£
եȡ_async/*¼°wls-wsat/*ÐÎʽµÄURL·¾¶»á¼û¡£¡£¡£¡£¡£¡£¡£