¡¾Ô­´´Îó²î¡¿Oracle WebLogic Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨¼´CVE-2019-2725²¹¶¡Èƹý£©

Ðû²¼Ê±¼ä 2019-06-17
0x01 Îó²îÐÎò


2019Äê4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬ £¬Oracle¹Ù·½Ðû²¼ÁËWebLogic wls9-async¼°wls-wsat×é¼þÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄ²¹¶¡£¡£¡£¡£¡£¡£¡£¨CVE-2019-2725£©£¬£¬£¬£¬£¬£¬ £¬https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html¡£¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£ÍøADLabµÚһʱ¼ä¶Ô¸Ã²¹¶¡¾ÙÐÐÁËÉîÈëÑо¿£¬£¬£¬£¬£¬£¬ £¬·¢Ã÷¸Ã²¹¶¡±£´æÇ徲ȱÏÝ£¬£¬£¬£¬£¬£¬ £¬ÔڵͰ汾JDKµÄÇéÐÎÖпÉÒÔ±»Èƹýµ¼ÖÂí§ÒâÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£ADLabÒÑÏòOracle¹Ù·½·´ÏìÁËCVE-2019-2725²¹¶¡ÈƹýµÄÎó²î£¬£¬£¬£¬£¬£¬ £¬²¢»ñµÃÁ˹ٷ½¼òÖ±ÈÏ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÎó²îÄÜʹ¹¥»÷ÕßÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬ £¬ÏÖÔÚ¹Ù·½²¹¶¡ÉÐδÐû²¼ÇÒÒÑÓÐÓû§Êܵ½ÒÉËÆ¸ÃÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬£¬ £¬½¨ÒéËùÓÐʹÓÃOracle WebLogicµÄÓû§¾¡¿ì×Ô¶¯°²ÅÅÏìÓ¦·À»¤¡£¡£¡£¡£¡£¡£¡£


0x02 Îó²îʱ¼äÖá


2019Äê6ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ £¬ADLab½«Îó²îÏêÇéÌá½»¸øOracle¹Ù·½£»£»£»


2019Äê6ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬ £¬Oracle¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈÐÞ¸´¡£¡£¡£¡£¡£¡£¡£


0x03 Ó°Ïì°æ±¾


Oracle WebLogic Server 10.3.6.0


0x04 Îó²îʹÓÃ


²âÊÔÇéÐΣºWebLogic Server 10.3.6.0 + CVE-2019-2725²¹¶¡


ʹÓÃÀú³Ì£º

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



0x05 ÔÝʱ½â¾ö¼Æ»®


¹Ù·½²¹¶¡Ç°µÄÔÝʱ·À»¤£º


ɾ³ýwls9_async_response.war¡¢wls_wsat.war¼°Ïà¹ØÎļþ¼Ð£¬£¬£¬£¬£¬£¬ £¬²¢ÖØÆôweblogicЧÀÍ¡£¡£¡£¡£¡£¡£¡£


եȡ_async/*¼°wls-wsat/*ÐÎʽµÄURL·¾¶»á¼û¡£¡£¡£¡£¡£¡£¡£


ʹÓÃ1.7¼°ÒÔÉϵÄjava°æ±¾ÔËÐÐWebLogic£¨Õë¶ÔÏÖÔÚÈö²¥µÄµÍ°æ±¾JDKʹÓã©¡£¡£¡£¡£¡£¡£¡£