¡¾Ç徲ͨ¸æ¡¿WebLogic¶à¸ö¸ßΣÎó²îͨ¸æ
2021-07-22
Ò». Îó²î¸ÅÊö
7ÔÂ21ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Oracle¹Ù·½Ðû²¼ÁË2021Äê7ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨Critical Patch Update£©£¬¹²ÐÞ¸´ÁË342¸ö²î±ðˮƽµÄÎó²î£¬ÆäÖаüÀ¨3¸öÓ°ÏìWebLogicµÄÑÏÖØÎó²î£¬Ê¹ÓÃÖØÆ¯ºóµÍ£¬½¨ÒéÓû§¾¡¿ì½ÓÄɲ½·¥£¬¶Ô´Ë´ÎµÄÎó²î¾ÙÐзÀ»¤¡£
CVE-2021-2382/CVE-2021-2394/CVE-2021-2397£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâ½á¹¹µÄT3»òIIOPÐÒéÇëÇ󣬿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬CVSSÆÀ·ÖΪ9.8
CVE-2021-2376/CVE-2021-2378£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýT3»òIIOPÐÒé·¢ËͶñÒâÇëÇ󣬿ÉÔì³ÉÄ¿µÄ·þÎñÆ÷¹ÒÆð»òÍ߽⣬CVSSÆÀ·ÖΪ7.5
CVE-2015-0254£º´ËÎó²î±£´æÓÚApache Standard TaglibsÖУ¬µ±Ó¦ÓóÌÐòʹÓà <x:parse> »ò <x:transform> ±êÇ©´¦Öóͷ£²»ÊÜÐÅÍеÄXMLÎĵµÊ±£¬1.2.3°æ±¾Ö®Ç°µÄ Apache Standard TaglibsÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃXSLT À©Õ¹Ö´ÐÐí§Òâ´úÂë»ò¾ÙÐÐXMLÍⲿʵÌå×¢Èë(XXE) ¹¥»÷£¬CVSSÆÀ·ÖΪ7.3
CVE-2021-2403£ºÎ´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýHTTP·¢ËͶñÒâÇëÇó£¬Î´ÊÚȨ»á¼ûÄ¿µÄ·þÎñÆ÷µÄijЩÊý¾Ý£¬CVSSÆÀ·ÖΪ5.3
²Î¿¼Á´½Ó£º
https://www.oracle.com/security-alerts/cpujul2021.html#AppendixFMW
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
WebLogic Server 10.3.6.0.0
WebLogic Server 12.1.3.0.0
WebLogic Server 12.2.1.3.0
WebLogic Server 12.2.1.4.0
WebLogic Server 14.1.1.0.0
Èý. Îó²î¼ì²â
3.1 ÍâµØ¼ì²â
¿ÉʹÓÃÈçÏÂÏÂÁî¶ÔWebLogic°æ±¾ºÍ²¹¶¡×°ÖõÄÇéÐξÙÐÐÅŲ顣
|
$ cd /Oracle/Middleware/wlserver_10.3/server/lib $ java -cp weblogic.jar weblogic.version |
ÔÚÏÔʾЧ¹ûÖУ¬ÈôÊÇûÓв¹¶¡×°ÖõÄÐÅÏ¢£¬Ôò˵Ã÷±£´æÎ£º¦£¬ÈçÏÂͼËùʾ£º
3.2 T3ÐÒé̽²â
Nmap¹¤¾ßÌṩÁËWebLogic T3ÐÒéµÄɨÃè¾ç±¾£¬¿É̽²â¿ªÆôT3·þÎñµÄWebLogicÖ÷»ú¡£ÏÂÁîÈçÏ£º
|
nmap -n -v -Pn –sV [Ö÷»ú»òÍø¶ÎµØµã] –p£¨Ä¬ÈÏ£©7001,7002 --script=weblogic-t3-info.nse |
ÈçÏÂͼºì¿òËùʾ£¬Ä¿µÄ¿ªÆôÁËT3ÐÒéÇÒWebLogic°æ±¾ÔÚÊÜÓ°Ïì¹æÄ£Ö®ÄÚ£¬ÈôÊÇÏà¹ØÖ°Ô±Ã»ÓÐ×°Öùٷ½µÄÇå¾²²¹¶¡£¬Ôò±£´æÎó²îΣº¦¡£
ËÄ. Îó²î·À»¤
4.1 ²¹¶¡¸üÐÂ
ÏÖÔÚOracleÒÑÐû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬ÇëÓû§²Î¿¼¹Ù·½Í¨¸æÊµÊ±ÏÂÔØÊÜÓ°Ïì²úÆ·¸üв¹¶¡£¬²¢²ÎÕÕ²¹¶¡×°ÖðüÖеÄreadmeÎļþ¾ÙÐÐ×°ÖøüУ¬ÒÔ°ü¹Üºã¾ÃÓÐÓõķÀ»¤¡£
×¢£ºOracle¹Ù·½²¹¶¡ÐèÒªÓû§³ÖÓÐÕý°æÈí¼þµÄÔÊÐíÕ˺ţ¬Ê¹ÓøÃÕ˺ÅÉϰ¶https://support.oracle.comºó£¬¿ÉÒÔÏÂÔØ×îв¹¶¡¡£
4.2 ÔÝʱ·À»¤²½·¥
ÈôÊÇÓû§ÔÝʱÎÞ·¨×°Öøüв¹¶¡£¬¿Éͨ¹ýÏÂÁв½·¥¶Ô¸ßΣÎó²î¾ÙÐÐÔÝʱ·À»¤£º
4.2.1 ÏÞÖÆT3ÐÒé»á¼û
Óû§¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶ÔʹÓÃT3ÐÒéÎó²îµÄ¹¥»÷¡£WebLogic ServerÌṩÁËÃûΪ weblogic.security.net.ConnectionFilterImpl µÄĬÈÏÅþÁ¬É¸Ñ¡Æ÷£¬´ËÅþÁ¬É¸Ñ¡Æ÷½ÓÊÜËùÓд«ÈëÅþÁ¬£¬¿Éͨ¹ý´ËÅþÁ¬É¸Ñ¡Æ÷ÉèÖùæÔò£¬¶ÔT3¼°T3sÐÒé¾ÙÐлá¼û¿ØÖÆ£¬Ïêϸ²Ù×÷°ì·¨ÈçÏ£º
1. ½øÈëWebLogic¿ØÖÆÌ¨£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬½øÈë“Çå¾²”Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷“ɸѡÆ÷”£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖá£
2. ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬²Î¿¼ÒÔÏÂд·¨£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÉèÖÃÇÐºÏÆóÒµÏÖÕæÏàÐεĹæÔò£º
|
127.0.0.1 * * allow t3 t3s ±¾»úIP ** allow t3 t3s ÔÊÐí»á¼ûµÄIP * * allow t3 t3s * * * deny t3 t3s |
|
ÅþÁ¬É¸Ñ¡Æ÷¹æÔòÃûÌÃÈçÏ£ºtarget localAddress localPort action protocols£¬ÆäÖУº · target Ö¸¶¨Ò»¸ö»ò¶à¸öҪɸѡµÄ·þÎñÆ÷¡£ · localAddress ¿É½ç˵·þÎñÆ÷µÄÖ÷»úµØµã¡£(ÈôÊÇÖ¸¶¨ÎªÒ»¸öÐǺŠ(*)£¬Ôò·µ»ØµÄÆ¥ÅäЧ¹û½«ÊÇËùÓÐÍâµØ IP µØµã¡£) · localPort ½ç˵·þÎñÆ÷ÕýÔÚ¼àÌýµÄ¶Ë¿Ú¡£(ÈôÊÇÖ¸¶¨ÁËÐǺţ¬ÔòÆ¥Åä·µ»ØµÄЧ¹û½«ÊÇ·þÎñÆ÷ÉÏËùÓпÉÓõĶ˿Ú)¡£ · action Ö¸¶¨ÒªÖ´ÐеIJÙ×÷¡£(Öµ±ØÐèΪ“allow”»ò“deny”¡£) · protocols ÊÇÒª¾ÙÐÐÆ¥ÅäµÄÐÒéÃûÁÐ±í¡£(±ØÐèÖ¸¶¨ÏÂÁÐÆäÖÐÒ»¸öÐÒ飺http¡¢https¡¢t3¡¢t3s¡¢giop¡¢giops¡¢dcom »ò ftp¡£) ÈôÊÇδ½ç˵ÐÒ飬ÔòËùÓÐÐÒé¶¼½«ÓëÒ»¸ö¹æÔòÆ¥Åä¡£ |
3. ÉúÑĺóÈô¹æÔòδÉúЧ£¬½¨ÒéÖØÐÂÆô¶¯WebLogic·þÎñ£¨ÖØÆôWebLogic·þÎñ»áµ¼ÖÂÓªÒµÖÐÖ¹£¬½¨ÒéÏà¹ØÖ°Ô±ÆÀ¹ÀΣº¦ºó£¬ÔÙ¾ÙÐвÙ×÷£©¡£ÒÔWindowsÇéÐÎΪÀý£¬ÖØÆô·þÎñµÄ°ì·¨ÈçÏ£º
½øÈëÓòËùÔÚĿ¼ÏµÄbinĿ¼£¬ÔÚWindowsϵͳÖÐÔËÐÐstopWebLogic.cmdÎļþÖÕÖ¹WebLogic·þÎñ£¬LinuxϵͳÖÐÔòÔËÐÐstopWebLogic.shÎļþ¡£
´ýÖÕÖ¹¾ç±¾Ö´ÐÐÍê³Éºó£¬ÔÙÔËÐÐstartWebLogic.cmd»òstartWebLogic.shÎļþÆô¶¯WebLogic£¬¼´¿ÉÍê³ÉWebLogic·þÎñÖØÆô¡£
4.2.2 ½ûÓÃIIOPÐÒé
Óû§¿Éͨ¹ý¹Ø±ÕIIOPÐÒé×è¶ÏÕë¶ÔʹÓÃIIOPÐÒéÎó²îµÄ¹¥»÷£¬²Ù×÷ÈçÏ£º
ÔÚWebLogic¿ØÖÆÌ¨ÖУ¬Ñ¡Ôñ“·þÎñ”->“AdminServer”->“ÐÒ锣¬×÷·Ï“ÆôÓÃIIOP”µÄ¹´Ñ¡¡£²¢ÖØÆôWebLogicÏîÄ¿£¬Ê¹ÉèÖÃÉúЧ¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







