jinri,oracleguanfangfabule7yuefendeguanjianbudinggengxincpu(critical patch update),qizhongbaohanguoneianquanyanjiurenyuanfaxiandeoracledegaoweiyuanchengdaimazhixingloudong(cve-2018-2893),tongguogailoudonggongjizhekeyizaiweishouquandeqingkuangxiayuanchengzhixingrenyidaima。
漏洞概述
亚博买球weblogicshimeiguooraclegongsichupindeyigeapplication server,queqiedeshuoshiyigejiyujavaeejiagoudezhongjianjian,weblogicshiyongyukaifa、jicheng、bushuheguanlidaxingfenbushiwebyingyong、wangluoyingyongheshujukuyingyongdejavayingyongfuwuqi。jiangjavadedongtaigongnenghejava enterprisebiaozhundeanquanxingyinrudaxingwangluoyingyongdekaifa、jicheng、bushuheguanlizhizhong。
亚博买球gailoudongtongguojrmpxieyiliyongrmijizhidequexiandadaozhixingrenyifanxuliehuadaimademude。gongjizhekeyizaiweishouquandeqingkuangxiajiangpayloadfengzhuangzait3xieyizhong,tongguoduit3xieyizhongdepayloadjinxingfanxuliehua,congershixianduicunzailoudongdeweblogiczujianjinxingyuanchenggongji,zhixingrenyidaimabingkehuoqumubiaoxitongdesuoyouquanxian。
漏洞危害
亚博买球tongguogailoudonggongjizhekeyizaiweishouquandeqingkuangxiayuanchengzhixingrenyidaima。
受影响范围
weblogic 10.3.6.0
weblogic 12.1.3.0
亚博买球weblogic 12.2.1.2
亚博买球weblogic 12.2.1.3
yishangjunweiguanfangzhichidebanben。
修复建议
1、guanzhuoracleguanfangcpugengxinbuding,jishijinxinggengxin。
2、kongzhit3xieyidefangwen:ciloudongchanshengyuweblogicdet3fuwu,yinciketongguokongzhit3xieyidefangwenlailinshizuduanzhenduigailoudongdegongji。dangkaifangweblogickongzhitaiduankou(morenwei7001duankou)shi,t3fuwuhuimorenkaiqi。juticaozuoruxia:
亚博买球diyibu:jinruweblogickongzhitai,zaibase_domaindepeizhiyemianzhong,jinru“anquan”xuanxiangkayemian,dianji“shaixuanqi”,jinrulianjieshaixuanqipeizhi。
dierbu:zailianjieshaixuanqizhongshuru:weblogic.security.net.connectionfilterimpl,zailianjieshaixuanqiguizezhongshuru:127.0.0.1 * * allow t3 t3s,0.0.0.0/0 * * deny t3 t3s(t3het3sxieyidesuoyouduankouzhiyunxubendifangwen)。
disanbu:baocunhouxuzhongxinqidong,guizefangkeshengxiao。
亚博买球3、shengjidaojdk-8u20yishangdebanben。