¡¾Ô­´´·ì϶¡¿WebLogic ·´ÐòÁл¯RCE·ì϶¹«¸æ£¨CVE-2021-2135£©

°ä²¼¹¦·ò 2021-04-22

·ì϶¸ÅÊö


Oracle¹Ù·½°ä²¼ÁË4Ô·ݵݲȫ²¹¶¡, ²¹¶¡ÖÐÔ̺¬8827Ì«Ñô¼¯ÍÅADLab·¢ÏÖ²¢µÚÒ»¹¦·òÌá½»¸ø¹Ù·½µÄ·ì϶ £¬£¬£¬£¬£¬£¬·ì϶±àºÅΪCVE-2021-2135¡£¡£¡£¡£¡£¡£·ì϶µÈ¼¶Îª¸ßΣ £¬£¬£¬£¬£¬£¬CVVSÆÀ·ÖΪ9.8·Ö¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚWebLogicT3ºÍ̸»òIIOPºÍ̸µÄͨѶ¹ý³ÌÖÐ £¬£¬£¬£¬£¬£¬Í¨¹ý¸Ã·ì϶ £¬£¬£¬£¬£¬£¬¹¥»÷Õß½«ÌìÉúµÄpayload·â×°ÔÚT3ºÍ̸»òIIOPºÍ̸ÖÐ £¬£¬£¬£¬£¬£¬ÔÚ·´ÐòÁл¯¹ý³ÌÖÐʵÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þµÄÔ¶³ÌËÁÒâ´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£


·ì϶¹¦·òÖá


2021Äê2Ô £¬£¬£¬£¬£¬£¬½«·ì϶ÏêÇéÌá½»¸ø¹Ù·½£»£»£»£»£»

2021Äê3Ô £¬£¬£¬£¬£¬£¬È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·×ÅÊÖ½¨¸´£»£»£»£»£»

2021Äê4ÔÂ21ÈÕ £¬£¬£¬£¬£¬£¬¹Ù·½°ä²¼Õýʽ²¹¶¡¡£¡£¡£¡£¡£¡£


Ó°Ïì°æ±¾


Weblogic 12.1.3.0.0

Weblogic 12.2.1.3.0

Weblogic 12.2.1.4.0

Weblogic 14.1.1.0.0

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾


·ì϶ÀûÓÃ


²âÊÔ»·¾³£ºWeblogic Server 12.2.1.3

·ì϶ÀûÓóÉЧ£º


1.png


¶ã±Ü¹æ»®


1¡¢Éý¼¶²¹¶¡

https://www.oracle.com/security-alerts/cpuapr2021.html


2¡¢½ÚÔìT3ºÍ̸µÄ½Ó¼û

´Ë·ì϶²úÉúÓÚWebLogicµÄT3·þÎñ £¬£¬£¬£¬£¬£¬Òò¶ø¿Éͨ¹ý½ÚÔìT3ºÍ̸µÄ½Ó¼ûÀ´Ò»Ê±×è¶ÏÕë¶Ô¸Ã·ì϶µÄ¹¥»÷¡£¡£¡£¡£¡£¡£µ±Ê¢¿ªWebLogic½ÚÔì´ó¼Ý¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê± £¬£¬£¬£¬£¬£¬T3·þÎñ»áĬÈÏ¿ªÆô¡£¡£¡£¡£¡£¡£
¾ßÌå²Ù×÷£ºa£©½øÈëWebLogic½ÚÔį̀ £¬£¬£¬£¬£¬£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖÐ £¬£¬£¬£¬£¬£¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ £¬£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡± £¬£¬£¬£¬£¬£¬½øÈëÏνÓɸѡÆ÷ÅäÖᣡ£¡£¡£¡£¡£

b£©ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl £¬£¬£¬£¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s £¬£¬£¬£¬£¬£¬0.0.0.0/0 * * deny t3 t3s(t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û)¡£¡£¡£¡£¡£¡£

c£©±£ÁôºóÐè³ÁÐÂÆô¶¯ £¬£¬£¬£¬£¬£¬¹æ¶¨·½¿ÉÉúЧ¡£¡£¡£¡£¡£¡£


2.png



8827Ì«Ñô¼¯ÍÅ»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Äê £¬£¬£¬£¬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬£¬£¬£¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£¡£¡£¡£¡£¡£½ØÖ¹Ä¿Ç° £¬£¬£¬£¬£¬£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶½ü1100¸ö £¬£¬£¬£¬£¬£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶1000Óà¸ö £¬£¬£¬£¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×£¡£¡£¡£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£¡£¡£¡£


adlab.jpg