¡¾Ô´´Îó²î¡¿WebLogic ·´ÐòÁл¯RCEÎó²îͨ¸æ£¨CVE-2021-2135£©
Ðû²¼Ê±¼ä 2021-04-22Îó²î¸ÅÊö
Oracle¹Ù·½Ðû²¼ÁË4Ô·ݵÄÇå¾²²¹¶¡, ²¹¶¡ÖаüÀ¨¼øºÚµ£±£ÍøADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÎó²î£¬£¬£¬£¬£¬£¬Îó²î±àºÅΪCVE-2021-2135¡£¡£¡£Îó²îÆ·¼¶Îª¸ßΣ£¬£¬£¬£¬£¬£¬CVVSÆÀ·ÖΪ9.8·Ö¡£¡£¡£¸ÃÎó²î±£´æÓÚWebLogicT3ÐÒé»òIIOPÐÒéµÄͨѶÀú³ÌÖУ¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«ÌìÉúµÄpayload·â×°ÔÚT3ÐÒé»òIIOPÐÒéÖУ¬£¬£¬£¬£¬£¬ÔÚ·´ÐòÁл¯Àú³ÌÖÐʵÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þµÄÔ¶³Ìí§Òâ´úÂëÖ´Ðй¥»÷¡£¡£¡£
Îó²îʱ¼äÖá
2021Äê2Ô£¬£¬£¬£¬£¬£¬½«Îó²îÏêÇéÌá½»¸ø¹Ù·½£»£»£»£»£»
2021Äê3Ô£¬£¬£¬£¬£¬£¬È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´£»£»£»£»£»
2021Äê4ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬¹Ù·½Ðû²¼Õýʽ²¹¶¡¡£¡£¡£
Ó°Ïì°æ±¾
Weblogic 12.1.3.0.0
Weblogic 12.2.1.3.0
Weblogic 12.2.1.4.0
Weblogic 14.1.1.0.0
ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾
Îó²îʹÓÃ
²âÊÔÇéÐΣºWeblogic Server 12.2.1.3
Îó²îʹÓÃЧ¹û£º
¹æ±Ü¼Æ»®
1¡¢Éý¼¶²¹¶¡
https://www.oracle.com/security-alerts/cpuapr2021.html
2¡¢¿ØÖÆT3ÐÒéµÄ»á¼û
´ËÎó²î±¬·¢ÓÚWebLogicµÄT3ЧÀÍ£¬£¬£¬£¬£¬£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶Ô¸ÃÎó²îµÄ¹¥»÷¡£¡£¡£µ±¿ª·ÅWebLogic¿ØÖÆÌ¨¶Ë¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê±£¬£¬£¬£¬£¬£¬T3ЧÀÍ»áĬÈÏ¿ªÆô¡£¡£¡£
Ïêϸ²Ù×÷£ºa£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£
b£©ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬£¬£¬£¬£¬£¬0.0.0.0/0 * * deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£
c£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£
¼øºÚµ£±£ÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î½ü1100¸ö£¬£¬£¬£¬£¬£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬£¬£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØÏµÍ³Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵ȡ£¡£¡£