¡¾Íþвͨ¸æ¡¿WeblogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨ CVE-2020-2546¡¢CVE-2020-2551£©
2020-01-15
Ò»¡¢¸ÅÊö
±±¾©Ê±¼ä2020Äê1ÔÂ15ÈÕ£¬OracleÐû²¼2020Äê1ÔÂÒªº¦²¹¶¡¸üУ¨Critical Patch Update£¬¼ò³ÆCPU£©£¬´Ë´Î¸üÐÂÐÞ¸´ÁË333¸öΣº¦Ë®Æ½²î±ðµÄÇå¾²Îó²î¡£ÆäÖÐ196¸öÎó²î¿É±»Ô¶³Ìδ¾Éí·ÝÈÏÖ¤µÄ¹¥»÷ÕßʹÓᣴ˴θüÐÂÉæ¼°Oracle Database Server¡¢Oracle Weblogic Server¡¢Oracle Java SE¡¢Oracle MySQLµÈ¶à¸ö²úÆ·¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÓ¦ÓÃÒªº¦²¹¶¡¸üÐÂÐÞ¸´³ÌÐò£¬¶ÔÎó²î¾ÙÐÐÐÞ¸´¡£
´Ë´ÎÐû²¼µÄ²¹¶¡£¬ÐÞ¸´ÁËWeblogicµÄÁ½¸ö¸ßΣÎó²î£¨CVE-2020-2546¡¢CVE-2020-2551£©£º
CVE-2020-2546
¸ÃÎó²îͨ¹ýT3ÐÒéʵÏÖʹÓᢹ¥»÷Õß¿Éͨ¹ý´ËÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬CVSSÆÀ·Ö¾ùΪ9.8¡£Ê¹ÓÃÖØÆ¯ºóµÍ¡£
CVE-2020-2551
¸ÃÎó²î¿ÉÒÔÈÆ¹ýOracle¹Ù·½ÔÚ2019Äê10Ô·ÝÐû²¼µÄ×îÐÂÇå¾²²¹¶¡¡£¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPÐÒéÔ¶³Ì»á¼ûWeblogic Server·þÎñÆ÷ÉϵÄÔ¶³Ì½Ó¿Ú£¬´«Èë¶ñÒâÊý¾Ý£¬´Ó¶ø»ñÈ¡·þÎñÆ÷ȨÏÞ²¢ÔÚδÊÚȨÇéÐÎÏÂÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£CVSSÆÀ·Ö9.8¡£
IIOPÐÒéÒÔJava½Ó¿ÚµÄÐÎʽ¶ÔÔ¶³Ì¹¤¾ß¾ÙÐлá¼û£¬Ä¬ÈÏÆôÓá£
²Î¿¼Á´½Ó£º
https://www.oracle.com/security-alerts/cpujan2020.html
¶þ¡¢Ó°Ïì¹æÄ£
CVE-2020-2546
ÊÜÓ°Ïì°æ±¾
- WebLogic Server 10.3.6.0.0
- WebLogic Server 12.1.3.0.0
CVE-2020-2551
ÊÜÓ°Ïì°æ±¾
- Weblogic Server 10.3.6.0.0
- Weblogic Server 12.1.3.0.0,
- Weblogic Server 12.2.1.3.0
- Weblogic Server 12.2.1.4.0
Èý¡¢Îó²î·À»¤
ÇëÓû§²Î¿¼±¾Îĸ½Â¼“ÊÜÓ°Ïì²úÆ·¼°²¹¶¡ÐÅÏ¢”ʵʱÏÂÔØÊÜÓ°Ïì²úÆ·¸üв¹¶¡£¬²¢²ÎÕÕ²¹¶¡×°ÖðüÖеÄreadmeÎļþ¾ÙÐÐ×°ÖøüУ¬ÒÔ°ü¹Üºã¾ÃÓÐÓõķÀ»¤¡£
×¢£ºOracle¹Ù·½²¹¶¡ÐèÒªÓû§³ÖÓÐÕý°æÈí¼þµÄÔÊÐíÕ˺ţ¬Ê¹ÓøÃÕ˺ÅÉϰ¶https://support.oracle.comºó£¬¿ÉÒÔÏÂÔØ×îв¹¶¡¡£
´Ë´ÎOracle¹Ù·½µÄCPU£¬Ö»Ðû²¼ÁË12.2.1.4.0°æ±¾µÄÐÞ¸´²¹¶¡£¬ÆäËû°æ±¾²¹¶¡½«ÓÚ2020Äê1ÔÂ31ÈÕÐû²¼£¬ÇëÏà¹ØÓû§ÊµÊ±¹Ø×¢£¬ÔÚ²¹¶¡Ðû²¼ºóʵʱװÖÃÐÞ¸´¡£

3.1 Îó²î»º½â²½·¥
ÈôÓû§ÔÝʱ²»¿É×°ÖÃ×îв¹¶¡£¬¿Éͨ¹ýÏÂÁв½·¥¶ÔÎó²î¾ÙÐÐÔÝʱ·À»¤£º
CVE-2020-2546
Óû§¿Éͨ¹ý½ûÓÃT3ÐÒ飬¶Ô´ËÎó²î¾ÙÐÐÔÝʱ»º½â£¬Ïêϸ²Ù×÷¿É²Î¿¼ÏÂÁÐÁ´½Ó“4.2.2 T3ÐÒé»á¼û¿ØÖÆ”²¿·Ö£º
https://mp.weixin.qq.com/s/YWTSyEVunQUordwxThrGwA
CVE-2020-2551
¿Éͨ¹ý¹Ø±ÕIIOPÐÒé¶Ô´ËÎó²î¾ÙÐлº½â¡£²Ù×÷ÈçÏ£º
ÔÚWeblogic¿ØÖÆÌ¨ÖУ¬Ñ¡Ôñ“·þÎñ”->”AdminServer”->”ÐÒ锣¬×÷·Ï“ÆôÓÃIIOP”µÄ¹´Ñ¡¡£²¢ÖØÆôWeblogicÏîÄ¿£¬Ê¹ÉèÖÃÉúЧ¡£

ËÄ¡¢CPUÐÞ¸´Îó²î×ܽá
´Ë´ÎÒªº¦²¹¶¡¸üУ¨CPU£©ÐÞ¸´µÄÎó²îÉæ¼°Oracle Database Server¡¢Oracle Weblogic Server¡¢Oracle Java SE¡¢Oracle MySQLµÈ¶à¸ö³£ÓòúÆ·¡£
Oracle¹Ù·½2020Äê1ÔÂÒªº¦²¹¶¡¸üÐÂÎó²î×ܽáÈçÏ£º
| ²úÆ· | Îó²î¸öÊý | δÊÚȨԶ³ÌʹÓøöÊý | ×î¸ßCVSSÆÀ·Ö |
| Oracle Database server | 12 | 3 | 7.7 |
| Oracle Communications Applications | 21 | 19 | 9.8 |
| Oracle Construction and Engineering Suite | 12 | 8 | 9.8 |
| Oracle E-Business Suite | 23 | 21 | 8.2 |
| Oracle Enterprise Manager Products Suite | 50 | 10 | 9.8 |
| Oracle Financial Services Applications | 24 | 6 | 7.5 |
| Oracle Food and Beverage Applications | 1 | 0 | 4.9 |
| Oracle Fusion Middleware | 38 | 30 | 9.8 |
| Oracle GraalVM Executive | 5 | 3 | 9.8 |
| Oracle Health Sciences Applications | 3 | 3 | 9.8 |
| Oracle Hospitality Applications | 5 | 2 | 7.5 |
| Oracle Hyperion Executive | 2 | 1 | 9.8 |
| Oracle iLearning Executive | 1 | 1 | 4.7 |
| Oracle Java SE | 12 | 12 | 8.1 |
| Oracle JD Edwards | 9 | 9 | 9.8 |
| Oracle MySQL | 19 | 6 | 7.5 |
| Oracle PeopleSoft Products | 15 | 12 | 9.8 |
| Oracle Retail Applications | 24 | 15 | 9.8 |
| Oracle Siebel CRM | 5 | 5 | 9.8 |
| Oracle Sun Systems Products | 18 | 9 | 9.8 |
| Oracle Supply Chain Products Suite | 8 | 8 | 9.6 |
| Oracle Support Tools | 1 | 1 | 6.1 |
| Oracle Utilities Applications | 4 | 4 | 9.8 |
| Oracle Virtualization | 22 | 3 | 8.2 |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ





