Adobe ColdFusionÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-28

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7838£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2019-7839£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ColdFusion 2018 update 3ÒÔ¼°Ö®Ç°°æ±¾
ColdFusion 2016 update 10ÒÔ¼°Ö®Ç°°æ±¾

ColdFusion 11 update 18ÒÔ¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


Adobe ColdFusionÊÇÃÀ¹ú°Â¶à±È£¨Adobe£©¹«Ë¾µÄÒ»Ì×¼±¾çÀûÓ÷¨Ê½¿ª·¢Æ½Ì¨¡£¡£¡£¡£¡£¡£¸Ãƽ̨Ô̺¬¼¯³É¿ª·¢»·¾³ºÍ¾ç±¾Ëµ»°¡£¡£¡£¡£¡£¡£ 


ColdfusionÈí¼þÖдæÔÚÁ½¸öÑϳÁÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¾ßÌåÈçÏ£º


CVE-2019-7838


¸Ã·ì϶ΪÎļþÀ©´óÃûºÚÃûµ¥Èƹý·ì϶£¬£¬£¬£¬£¬µ±ÎļþÉÏÔØÄ¿Â¼¿Éͨ¹ýWeb½Ó¼ûʱ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶½øÐжñÒâ¹¥»÷£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


CVE-2019-7839


JNBridgeÊÇÒ»ÖÖ¼¯³ÉJavaºÍ.NETÀûÓ÷¨Ê½´úÂëµÄ¼¼Êõ¡£¡£¡£¡£¡£¡£¸Ã¼¼Êõͨ¹ýÉè¼ÆÔÊÐí²»ÊÜÏ޶ȽӼûÔ¶³ÌJavaÔËÐÐʱµÄ»·¾³£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÖ´ÐÐËÁÒâ´úÂëºÍϵͳºÅÁî¡£¡£¡£¡£¡£¡£


ÔÚWindowsÉÏÔËÐеÄColdfusion·þÎñÆ÷¹«¿ªJNBridge TCP¶Ë¿Ú6093»ò6095ÉϵÄÍøÂçÕìÌýÆ÷¡£¡£¡£¡£¡£¡£¿ÉÄܽӼû¸Ã·þÎñµÄ¹¥»÷ÕßÄܹ»Ö´ÐÐËÁÒâ²Ù×÷Java´úÂë»òϵͳºÅÁî¡£¡£¡£¡£¡£¡£Ä¬ÈÏÇé¿öÏ£¬£¬£¬£¬£¬´Ë·þÎñÒÔ×î¸ßȨÏÞ£¨SYSTEM£©ÔËÐÓ×£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýJNBridge¼¼Êõ²»ÊÜÏ޶ȵؽӼûÔ¶³ÌJavaÔËÐÐʱ»·¾³£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÖ´ÐÐËÁÒâ´úÂëºÍϵͳºÅÁî¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


CVE-2019-7838


ÔÝÎÞPOC/EXP


CVE-2019-7839


EXP:https://cxsecurity.com/issue/WLB-2019060172


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://helpx.adobe.com/security/products/coldfusion/apsb19-27.html


²Î¿¼Á´½Ó


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201906-520
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201906-514