2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·£»Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©

Ðû²¼Ê±¼ä 2020-02-21

1.ÖйúÈËÃñÒøÐÐÐû²¼2020°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÖйúÈËÃñÒøÐÐÏ·¢¡¶¹ØÓÚ<ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶>ÐÐÒµ±ê×¼µÄ֪ͨ¡·£¨Òø·¢[2020]35ºÅ£©£¬Ðû²¼ÐÂ°æ¡¶ÍøÉÏÒøÐÐϵͳÐÅÏ¢Ç徲ͨÓù淶¡·(JR/T 0068-2020)£¬¸Ã°æ±¾ÊÇ2012°æ¹æ·¶(JR/T 0068-2012)µÄÌæ»»ÐÞ¶©°æ±¾¡£ÐÂ°æ¹æ·¶ÓÐÈý¸öÖØµãÐÞ¶©ÄÚÈÝ£º1¡¢Õë¶ÔÐÂÊÖÒÕ·ºÆðºÍÓ¦ÓÃÌá³öÁËеÄÇå¾²ÒªÇó£¨ÀýÈçÔöÌíÁËÐéÄ⻯¡¢ÔÆÅÌËãÇå¾²Ïà¹ØÒªÇó£¬ÔöÌí¹úÃÜSMϵÁÐËã·¨Ïà¹ØµÄÇå¾²ÒªÇó£¬ÔöÌí¶ÔÇå¾²µ¥Î»ºÍÒÆ¶¯ÖÕ¶ËÖ§¸¶¿ÉÐÅÇéÐÎÏà¹ØÒªÇ󣩣»2¡¢¾ÍеÄÓªÒµºÍî¿ÏµÒªÇó¾ÙÐÐÁËÔö²¹ºÍÃ÷È·£¨ÀýÈçÔöÌíÁËÌõÂëÖ§¸¶¡¢ÉúÒâÇå¾²ËøºÍ¢ò¡¢¢óÀàÕË»§µÄÏà¹ØÒªÇ󣩣»3¡¢ÖØÐÂÊáÀí²¢ÌáÉý¹ØÓÚÓªÒµÒ»Á¬ÐÔÓëÔÖÄѻָ´¡¢Çå¾²ÊÂÎñÓëÓ¦¼±ÏìÓ¦µÄÇå¾²ÒªÇó¡£


Ô­ÎÄÁ´½Ó£º

https://www.cebnet.com.cn/20200219/102639904.html


2.˼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷ÌØÈ¨ÕË»§ºÍ¾²Ì¬ÃÜÂ룬½¨ÒéÁ¬Ã¦ÐÞ¸´


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


˼¿ÆÐÞ¸´ÆäÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM£©ÖеÄÌØÈ¨ÕË»§¾²Ì¬ÃÜÂëÎó²î£¬¸ÃÎó²î£¨CVE-2020-3158£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬Ëü¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÈ¨½Ï¸ßµÄÕÊ»§»á¼ûϵͳµÄÃô¸Ð²¿·Ö¡£Ë¼¿ÆÌåÏÖ£¬¡°¸ÃÎó²îÊÇÓÉÓÚijϵͳÕË»§¾ßÓÐĬÈϺ;²Ì¬ÃÜÂëÇÒ²¢²»ÊÜϵͳÖÎÀíÔ±¿ØÖƶøÔì³ÉµÄ¡£¡±SSM On-PremϵͳֻÓÐÔÚÆôÓÃÁ˸߿ÉÓÃÐÔ£¨HA£©¹¦Ð§Ê±²ÅÒ×Êܹ¥»÷£¬µ«¸Ã¹¦Ð§Ä¬ÈÏδÆôÓá£Ë¼¿ÆÖÒÑԳƣ¬¹¥»÷Õß²»ÐèÒªÓÐÓõĵǼ¾Í¿ÉÒÔÌᳫ¹¥»÷£¬²¢ÇÒ¿ÉÒÔʹÓøßÌØÈ¨Ä¬ÈÏÕÊ»§À´ÅþÁ¬Ò×Êܹ¥»÷µÄϵͳ£¬»ñµÃ¶ÔϵͳÊý¾ÝµÄ¶Áд»á¼ûȨÏÞ£¬²¢¸ü¸ÄÆäÉèÖá£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-critical-bug-static-password-in-smart-software-manager-patch-now-says-cisco/


3.AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬ÐÞ¸´Á½¸ö´úÂëÖ´ÐÐÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


AdobeÐû²¼½ôÆÈÇå¾²¸üУ¬ÐÞ¸´Æä²úÆ·ÖеÄÁ½¸ö´úÂëÖ´ÐÐÎó²î¡£µÚÒ»¸öÎó²î£¨CVE-2020-3764£©Êǿɵ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÔ½½çдÎó²î£¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe Media Encoder 14.0¼°¸üÔç°æ±¾¡£µÚ¶þ¸öÎó²î£¨CVE-2020-3765£©Ò²ÊÇÓÉÔ½½çдµ¼ÖµĴúÂëÖ´ÐÐÎó²î£¬µ«¹¥»÷Ö»ÄÜÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖоÙÐУ¬¸ÃÎó²îÓ°ÏìÁËWindowsƽ̨ÉϵÄAdobe After Effects°æ±¾16.1.2¼°¸üÔç°æ±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-releases-out-of-schedule-fixes-for-critical-vulnerabilities/


4.Apache TomcatÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Apache Tomcat·þÎñÆ÷±£´æÎļþ°üÀ¨Îó²î£¨CVE-2020-1938£©£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¶ÁÈ¡»ò°üÀ¨TomcatÉÏËùÓÐwebappĿ¼ÏµÄí§ÒâÎļþ£¬È磺webappÉèÖÃÎļþ»òÔ´´úÂëµÈ¡£¸ÃÎó²îÓëTomcat AJPЭÒéÓйØ£¬Tomcat AJP ConnectorĬÈÏÉèÖÃϼ´Îª¿ªÆô״̬£¬²¢ÇÒ¼àÌý¶Ë¿Ú8009¡£¸ÃÎó²îÓ°ÏìÁËTomcat 6/7/8/9È«°æ±¾£¬Apache¹Ù·½ÒÑÐû²¼9.0.31¡¢8.5.51¼°7.0.100°æ±¾Õë¶Ô´ËÎó²î¾ÙÐÐÐÞ¸´£¬½¨ÒéÓû§ÏÂÔØÊ¹Óá£ÓÉÓÚTomcat 6ÒѾ­×èֹά»¤£¬½¨ÒéÓû§Éý¼¶µ½×îÐÂÊÜÖ§³ÖµÄTomcat°æ±¾ÒÔÃâÔâÊܹ¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2020-10487


5.ÃÀ¹ú²ÎÒéÔ±Ìá³öÐÂÊý¾Ý±£»¤·¨°¸£¬½¨Ò齨ÉèÊý¾Ý±£»¤¾Ö


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÀ¹úŦԼÖݲÎÒéÔ±¼ª¶û˹²¼À¼µÂ£¨Kirsten Gillibrand£©ÉÏÖÜÐû²¼ÁËÒ»ÏîÁ¢·¨²Ý°¸£¬¸Ã·¨°¸½«½¨ÉèÒ»¸ö×ÔÁ¦µÄÁª°î»ú¹¹£¬¼´Êý¾Ý±£»¤¾Ö£¬Ö¼ÔÚ½ç˵¡¢ÖٲúÍÖ´ÐÐÊý¾Ý±£»¤¹æÔò¡£Õâλ²ÎÒéÔ±ÒÔΪ£¬¡¶Áª°îÉÌҵίԱ»á·¨¡·²¢Î´½â¾öÊý¾Ý±£»¤·½ÃæµÄÌôÕ½£¬¶øÃÀ¹úÔÚÓ¦¶ÔÊý¾Ý±£»¤ÌôÕ½ºÍÊý×Öʱ´úµÄÐí¶àÆäËüÌôÕ½·½ÃæÂäÎ飬ÃÀ¹úҲûÓÐÒ»¸öרÃŵĻú¹¹À´Ö´ÐÐÊý¾ÝÒþ˽¹æÔò¡£ÈôÊǸ÷¨°¸»ñµÃͨ¹ý£¬½«ÊÊÓÃÓÚÈκÎÊÕÈëÁè¼Ý2500ÍòÃÀÔª£¬»òÖÎÀí5Íò»ò¸ü¶àÈ˵ÄСÎÒ˽¼ÒÊý¾ÝµÄ¹«Ë¾¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/us-senator-proposes-new-data-protection-bill-37232e0b


6.¸çÂ×±ÈÑÇCommunity CareÔâÀÕË÷¹¥»÷£¬»¼ÕßÊý¾Ý¿ÉÄÜй¶


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¸çÂ×±ÈÑÇÊ×¶¼µØÇø×î´óµÄ×ÔÁ¦Ò½ÁÆ»ú¹¹Community Care»¼ÕßÊý¾Ý¿ÉÄÜй¶£¬¸ÃÊÂÎñÊÇÓÉÆä»á¼ÆÊ¦ÊÂÎñËùBSTÔâµ½ÀÕË÷Èí¼þ¹¥»÷µ¼ÖµÄ¡£BSTÓÚ2019Äê12ÔÂ7ÈÕ·¢Ã÷°üÀ¨¿Í»§»á¼ÆºÍ˰ÊÕÊý¾ÝÔÚÄڵIJ¿·ÖÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬µ«¸Ã¹«Ë¾Äܹ»Ê¹Óñ¸·Ý»¹Ô­Îļþ¡£ÔÚÖ®ºóµÄÊÓ²ìÖУ¬¸Ã¹«Ë¾ÓÚ2ÔÂ5ÈÕÈ·Èϲ¿·Ö»¼ÕßµÄÐÅÏ¢¿ÉÄÜй¶£¬ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÉúÈÕ¡¢ÌõÄ¿ºÅÂëºÍÕʵ¥´úÂ룬µ«²»°üÀ¨ÒøÐÐÕʺš¢Éç»áÇå¾²ºÅÂëºÍ²¡ÀúÐÅÏ¢¡£BST»òCommunity Care¶¼Ã»ÓÐ͸¶ÊÜÓ°ÏìµÄ»¼ÕßÈËÊý¡£


Ô­ÎÄÁ´½Ó£º

https://dailygazette.com/article/2020/02/19/data-breach-community-Care-physicians