Áú8¹ú¼Êµç×Óƽ̨

long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾ Ê×Ò³long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾Çå¾²·þÎñlong8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾Ç徲ͨ¸æ long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾
ÕýÎÄ

Weblogic¶à¸ö¸ßΣÎó²îÇå¾²Ô¤¾¯Ó뽨Òé

Ðû²¼Ê±¼ä£º2021-07-23 11:07   ä¯ÀÀ´ÎÊý£º6472

¿ËÈÕ £¬Oracle¹Ù·½Ðû²¼ÁË7Ô·ݵÄÒªº¦²¹¶¡,ÆäÖаüÀ¨¶à¸ö¸ßΣµÄWeblogic×é¼þÎó²î £¬°üÀ¨£º CVE-2021-2397¡¢CVE-2021-2376¡¢CVE-2021-2378¡¢CVE-2021-2382¡¢CVE-2021-2403¡¢CVE-2021-2394 £¬¹¥»÷Õß¿ÉÄÜʹÓôËЩÎó²î»ñÈ¡WebLogic·þÎñÆ÷ȨÏÞ¡£¼øÓÚÎó²îΣº¦½Ï¸ß £¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì¸üйٷ½Ðû²¼µÄÇå¾²²¹¶¡¡£


¡¾Îó²îÐÎò¡¿

΢ÐÅͼƬ_20210723113206.png

ÆäÖж¨ÎªÑÏÖØCVE-2021-2397¡¢CVE-2021-2382¡¢CVE-2021-2394 £¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýIIOP¡¢T3ЭÒé¶Ô±£´æÎó²îµÄOracle WebLogic Server×é¼þ¾ÙÐй¥»÷¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ½ÓÊÜOracle WebLogic Server¡£


¡¾Îó²îÓ°Ïì°æ±¾¡¿

CVE-2021-2397¡¢CVE-2021-2382¡¢CVE-2021-2394Îó²îÓ°Ïì°æ±¾£º

Oracle WebLogic Server 10.3.6.0.0

Oracle WebLogic Server 12.1.3.0.0

Oracle WebLogic Server 12.2.1.3.0

Oracle WebLogic Server 12.2.1.4.0

Oracle WebLogic Server 14.1.1.0.0

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾


¡¾ÐÞ¸´¼Æ»®¡¿

Oracle¹Ù·½ÒѾ­ÔÚ2021Äê7ÔÂÒªº¦²¹¶¡¸üÐÂÖÐÐÞ¸´Á˸ÃÎó²î £¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶¸üоÙÐзÀ»¤¡£

×¢£ºOracle¹Ù·½²¹¶¡ÐèÒªÓû§³ÖÓÐÕý°æÈí¼þµÄÔÊÐíÕ˺Š£¬Ê¹ÓøÃÕ˺ÅÉÏ°¶https://support.oracle.comºó £¬¿ÉÒÔÏÂÔØ×îв¹¶¡¡£

Ïà¹ØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpujul2021.html 

 

ÔÝʱ½â¾ö¼Æ»®£º

ÔÝʱÐÞ¸´½¨Òé±£´æÒ»¶¨Î£º¦ £¬½¨ÒéÓû§Æ¾Ö¤ÓªÒµÏµÍ³ÏÖÕæÏàÐÎÆÀ¹ÀºóÑ¡Ôñ½ÓÄÉÔÝʱÐÞ¸´¼Æ»®¡£

Ò»¡¢½ûÓÃT3ЭÒé

Îó²î±¬·¢ÓÚWebLogicµÄT3·þÎñ £¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ЭÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶Ô¸ÃÎó²îµÄ¹¥»÷¡£µ±¿ª·ÅWebLogic¿ØÖÆ̨¶Ë¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê± £¬T3·þÎñ»áĬÈÏ¿ªÆô¡£

Ïêϸ²Ù×÷£º

£¨1£©½øÈëWebLogic¿ØÖÆ̨ £¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖÐ £¬½øÈë¡°Çå¾²¡±Ñ¡ÏҳÃæ £¬µã»÷¡°É¸Ñ¡Æ÷¡± £¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖá£

£¨2£©ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl £¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s £¬0.0.0.0/0 * * deny t3 t3s£¨t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û£©¡£

£¨3£©ÉúÑĺóÐèÖØÐÂÆô¶¯ £¬¹æÔò·½¿ÉÉúЧ¡£


ͼƬ1.png


¶þ¡¢½ûÓÃIIOPЭÒé

Óû§¿Éͨ¹ý¹Ø±ÕIIOPЭÒé×è¶ÏÕë¶ÔʹÓÃIIOPЭÒéÎó²îµÄ¹¥»÷ £¬²Ù×÷ÈçÏ£º

ÔÚWeblogic¿ØÖÆ̨ÖÐbase_domainÉèÖÃÒ³Ãæ £¬ÒÀ´Îµã»÷¡°ÇéÐΡ±-¡°·þÎñÆ÷¡± £¬ÔÚ·þÎñÆ÷ÉèÖÃÒ³ÃæÖÐÑ¡Ôñ¶ÔÓ¦µÄ·þÎñÆ÷ºó £¬Çл»µ½¡°Ð­Ò顱-¡°IIOP¡±Ñ¡Ï £¬×÷·Ï¹´Ñ¡¡°ÆôÓà IIOP¡± £¬²¢ÖØÆôWeblogicÏîÄ¿ÉúЧ¡£


ͼƬ2.png


Èý¡¢ÔÝʱ¹Ø±Õºǫ́

¿ÉÔÝʱ¹Ø±Õºǫ́/console/console.portal¡¢/console/consolejndi.portal¶ÔÍâ»á¼û¡£


Áú8¹ú¼Êµç×Óƽ̨ °æȨËùÓÐ  ÁªÏµ: hxzhb@heidun.net ÃöICP±¸06011901ºÅ ? 1999-2024 Fujian Strait Information Corporation. All Rights Reserved.
long8-Áú8(¹ú¼Ê)Ψһ¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÍøÕ¾µØͼ