¡¾Ô­´´Îó²î¡¿WebLogic Blind XXEÎó²î£¨CVE-2019-2647£©

Ðû²¼Ê±¼ä 2019-04-17
Îó²î±àºÅ£º CVE-2019-2647
Îó²îȪԴ£º¿­Ðý¹ú¼ÊÓÎÏ·ADLab
Ðû²¼Ê±¼ä£º2019Äê4ÔÂ17ÈÕ

Îó²î¸ÅÊö


2019Äê4ÔÂ17ÈÕ£¬£¬Oracle¹Ù·½Ðû²¼4Ô·ÝÇå¾²²¹¶¡, ²¹¶¡ÖаüÀ¨¿­Ðý¹ú¼ÊÓÎÏ·ADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸øOracle¹Ù·½µÄWebLogic Blind XXEÎó²î£¬£¬Îó²î±àºÅΪCVE-2019-2647¡£¡£¡£¡£¡£¡£Ê¹ÓøÃÎó²î£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬£¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£¡£¡£¡£


Îó²îʱ¼äÖá


2019Äê1ÔÂ9ÈÕ£º½«Îó²îÏêÇéÌá½»¸ø¹Ù·½£»£»£»£»£»
2019Äê1ÔÂ17ÈÕ£ºÈ·ÈÏÎó²î±£´æ²¢×îÏÈÐÞ¸´£»£»£»£»£»
2019Äê4ÔÂ17ÈÕ£ºOracle¹Ù·½Ðû²¼Çå¾²²¹¶¡¡£¡£¡£¡£¡£¡£

Ó°Ïì°æ±¾


WebLogic 10.3.6.0
WebLogic 12.1.3.0
WebLogic 12.2.1.2

WebLogic 12.2.1.3


Îó²îʹÓÃ


²âÊÔÇéÐΣºWebLogic Server 10.3.6.0£¨´ò²¹p28343311_1036_Generic£©


Îó²îʹÓÃЧ¹û£º

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾

¹æ±Ü¼Æ»®


1¡¢Éý¼¶²¹¶¡


Oracle¹Ù·½¸üÐÂÁ´½ÓµØµã£ºhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html ¡£¡£¡£¡£¡£¡£


2¡¢¿ØÖÆT3ЭÒéµÄ»á¼û


WebLogic Blind XXEÎó²î±¬·¢ÓÚWebLogicµÄT3ЧÀÍ£¬£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ЭÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶Ô¸ÃÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£µ±¿ª·ÅWebLogic¿ØÖÆÌ¨¶Ë¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê±£¬£¬T3ЧÀÍ»áĬÈÏ¿ªÆô¡£¡£¡£¡£¡£¡£


Ïêϸ²Ù×÷£º


£¨1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£¡£¡£¡£


£¨2£©ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬£¬0.0.0.0/0 * * deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£¡£¡£¡£


£¨3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£¡£¡£¡£


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾