2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·£»£»£»£»£»£»Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©
°ä²¼¹¦·ò 2020-02-211.ÖйúÈËÃñÒøÐа䲼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·
ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶>ÐÐÒµ³ß¶ÈµÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬£¬£¬£¬£¬£¬°ä²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢°²È«Í¨Óù淶¡·(JR/T 0068-2020)£¬£¬£¬£¬£¬£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄ´úÌæ¶©Õý°æ±¾¡£¡£¡£¡£¡£ÐÂ°æ¹æ·¶ÓÐÈý¸ö³Áµã¶©ÕýÄÚÈÝ£º1¡¢Õë¶Ôм¼Êõ³öÏÖºÍÀûÓÃÌá³öÁËÐµİ²È«ÒªÇó£¨ÀýÈçÔö³¤ÁËÐé¹¹»¯¡¢ÔÆÍÆË㰲ȫÓйØÒªÇ󣬣¬£¬£¬£¬£¬Ôö³¤¹úÃÜSMϵÁÐËã·¨ÓйصݲȫҪÇ󣬣¬£¬£¬£¬£¬Ôö³¤¶Ô°²È«µ¥ÔªºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅ»·¾³ÓйØÒªÇ󣩣»£»£»£»£»£»2¡¢¾ÍеÄÒµÎñºÍ¼à¹ÜÒªÇó½øÐÐÁ˲¹³äºÍÃ÷È·£¨ÀýÈçÔö³¤ÁËÌõÂëÖ§¸¶¡¢ÂòÂô°²È«ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÓйØÒªÇ󣩣»£»£»£»£»£»3¡¢³ÁÐÂÊáÀí²¢ÌáÉý¹ØÓÚÒµÎñÂ½ÐøÐÔÓë¿àÄѸ´Ô¡¢°²È«ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄ°²È«ÒªÇ󡣡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cebnet.com.cn/20200219/102639904.html
2.˼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷ÌØÈ¨ÕË»§ºÍ¾²Ì¬ÃÜÂ룬£¬£¬£¬£¬£¬½¨ÒéÁ¢¿Ì½¨¸´
˼¿Æ½¨¸´ÆäÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM£©ÖеÄÌØÈ¨ÕË»§¾²Ì¬ÃÜÂë·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2020-3158£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬£¬Ëü¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÈ¨½Ï¸ßµÄÕÊ»§½Ó¼ûϵͳµÄÃô¸Ð²¿ÃÅ¡£¡£¡£¡£¡£Ë¼¿Æ°µÊ¾£¬£¬£¬£¬£¬£¬¡°¸Ã·ì϶ÊÇÓÉÓÚijϵͳÕË»§ÓµÓÐĬÈϺ;²Ì¬ÃÜÂëÇÒ²¢²»ÊÜϵͳÖÎÀíÔ±½ÚÔì¶øÔì³ÉµÄ¡£¡£¡£¡£¡£¡±SSM On-PremϵͳֻÓÐÔÚÆôÓÃÁ˸߿ÉÓÃÐÔ£¨HA£©Ö°ÄÜʱ²ÅÒ×Êܹ¥»÷£¬£¬£¬£¬£¬£¬µ«¸ÃÖ°ÄÜĬÈÏδÆôÓᣡ£¡£¡£¡£Ë¼¿ÆÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬¹¥»÷Õß²»±ØÒªÓÐЧµÄµÇ¼¾ÍÄܹ»ÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬²¢ÇÒÄܹ»Ê¹ÓøßÌØÈ¨Ä¬ÈÏÕÊ»§À´ÏνÓÒ×Êܹ¥»÷µÄϵͳ£¬£¬£¬£¬£¬£¬»ñµÃ¶ÔϵͳÊý¾ÝµÄ¶Áд½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬²¢¸ü¸ÄÆäÉèÖᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cisco-critical-bug-static-password-in-smart-software-manager-patch-now-says-cisco/
3.Adobe°ä²¼´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Á½¸ö´úÂëÖ´Ðзì϶
Adobe°ä²¼´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´Æä²úÆ·ÖеÄÁ½¸ö´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶£¨CVE-2020-3764£©Êǿɵ¼ÖÂËÁÒâ´úÂëÖ´ÐеÄÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËWindowsƽ̨ÉϵÄAdobe Media Encoder 14.0¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶£¨CVE-2020-3765£©Ò²ÊÇÓÉÔ½½çдµ¼ÖµĴúÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬µ«¹¥»÷Ö»ÄÜÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖнøÐУ¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËWindowsƽ̨ÉϵÄAdobe After Effects°æ±¾16.1.2¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-releases-out-of-schedule-fixes-for-critical-vulnerabilities/
4.Apache TomcatÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©
Apache Tomcat·þÎñÆ÷´æÔÚÎļþÔ̺¬·ì϶£¨CVE-2020-1938£©£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶¶ÁÈ¡»òÔ̺¬TomcatÉÏËùÓÐwebappĿ¼ÏµÄËÁÒâÎļþ£¬£¬£¬£¬£¬£¬È磺webappÅäÖÃÎļþ»òÔ´´úÂëµÈ¡£¡£¡£¡£¡£¸Ã·ì϶ÓëTomcat AJPºÍ̸Óйأ¬£¬£¬£¬£¬£¬Tomcat AJP ConnectorĬÈÏÅäÖÃϼ´Îª¿ªÆô״̬£¬£¬£¬£¬£¬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËTomcat 6/7/8/9È«°æ±¾£¬£¬£¬£¬£¬£¬Apache¹Ù·½ÒѰ䲼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´Ë·ì϶½øÐн¨¸´£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÏÂÔØÊ¹Óᣡ£¡£¡£¡£ÓÉÓÚTomcat 6ÒѾÖÕ³¡ÊØ»¤£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâ·ê¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487
5.ÃÀ¹ú²ÎÒéÔ±Ìá³öÐÂÊý¾Ý±£»£»£»£»£»£»¤·¨°¸£¬£¬£¬£¬£¬£¬½¨Òé³ÉÁ¢Êý¾Ý±£»£»£»£»£»£»¤¾Ö
ÃÀ¹úŦԼÖݲÎÒéÔ±¼ª¶û˹²¼À¼µÂ£¨Kirsten Gillibrand£©ÉÏÖܰ䲼ÁËÒ»ÏîÁ¢·¨²Ý°¸£¬£¬£¬£¬£¬£¬¸Ã·¨°¸½«³ÉÁ¢Ò»¸ö¶ÀÁ¢µÄÁª¹ú»ú¹¹£¬£¬£¬£¬£¬£¬¼´Êý¾Ý±£»£»£»£»£»£»¤¾Ö£¬£¬£¬£¬£¬£¬Ö¼ÔÚ½ç˵¡¢ÖٲúÍÖ´ÐÐÊý¾Ý±£»£»£»£»£»£»¤¹æ¶¨¡£¡£¡£¡£¡£Õâλ²ÎÒéÔ±ÒÔΪ£¬£¬£¬£¬£¬£¬¡¶Áª¹úÒµÎñίԱ»á·¨¡·²¢Î´½â¾öÊý¾Ý±£»£»£»£»£»£»¤·½ÃæµÄÌôÕ½£¬£¬£¬£¬£¬£¬¶øÃÀ¹úÔÚÓ¦¶ÔÊý¾Ý±£»£»£»£»£»£»¤ÌôÕ½ºÍÊý×ÖʱÆÚµÄºÜ¶àÆäËüÌôÕ½·½ÃæÂäºó£¬£¬£¬£¬£¬£¬ÃÀ¹úҲûÓÐÒ»¸öרÃŵĻú¹¹À´Ö´ÐÐÊý¾ÝÒþÖԹ涨¡£¡£¡£¡£¡£ÈôÊǸ÷¨°¸»ñµÃͨ¹ý£¬£¬£¬£¬£¬£¬½«ºÏÓÃÓÚÈκÎÊÕÈ볬¹ý2500ÍòÃÀÔª£¬£¬£¬£¬£¬£¬»òÖÎÀí5Íò»ò¸ü¶àÈ˵ÄÓ×ÎÒÊý¾ÝµÄ¹«Ë¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/us-senator-proposes-new-data-protection-bill-37232e0b
6.¸çÂ×±ÈÑÇCommunity CareÔâÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬»¼ÕßÊý¾Ý¿ÉÄÜй¶
¸çÂ×±ÈÑÇÊ×¶¼µØÓò×î´óµÄ¶ÀÁ¢Ò½ÁÆ»ú¹¹Community Care»¼ÕßÊý¾Ý¿ÉÄÜй¶£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÊÇÓÉÆä¹ÜÕÊʦÊÂÎñËùBSTÔâµ½ÀÕË÷Èí¼þ¹¥»÷µ¼Öµġ£¡£¡£¡£¡£BSTÓÚ2019Äê12ÔÂ7ÈÕ·¢ÏÖÔ̺¬¿Í»§¹ÜÕʺÍ˰ÊÕÊý¾ÝÔÚÄڵIJ¿ÃÅÍøÂçϰȾÁËÀÕË÷²¡¶¾£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾¿ÉÄÜʹÓñ¸·Ý»¹ÔÎļþ¡£¡£¡£¡£¡£ÔÚÖ®ºóµÄµ÷²éÖУ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ2ÔÂ5ÈÕÈ·Èϲ¿ÃÅ»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢Ìõ¿îºÅÂëºÍÕʵ¥´úÂ룬£¬£¬£¬£¬£¬µ«²»Ô̺¬ÒøÐÐÕʺš¢Éç»á°²È«ºÅÂëºÍ²¡ÀúÐÅÏ¢¡£¡£¡£¡£¡£BST»òCommunity Care¶¼Ã»ÓÐй©ÊÜÓ°ÏìµÄ»¼ÕßÈËÊý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://dailygazette.com/article/2020/02/19/data-breach-community-Care-physicians


¾©¹«Íø°²±¸11010802024551ºÅ