WebLogic¸ßΣÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-16Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-2891£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
WebLogic 10.3.6.0.0
WebLogic 12.1.3.0.0
WebLogic 12.2.1.3.0
Îó²î¸ÅÊö
WebLogicÊÇOracle¹«Ë¾³öÆ·µÄ»ùÓÚJavaEE ¼Ü¹¹µÄÖÐÐļþ£¬ÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽ Web Ó¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦Óá£
Oracle¹Ù·½Ðû²¼ÁË2019Äê10ÔµÄÑÏÖØ²¹¶¡¸üÐÂCPU£¨Critical Patch Update£©£¬ÆäÖÐÐÞ¸´ÁËWebLogic ±£´æÓÚConsole×é¼þÖеÄÒ»¸ö¸ßΣÎó²î£¨CVE-2019-2891£©¡£
¹¥»÷ÕßÔÚδÊÚȨµÄÇéÐÎÏ£¬¿ÉÒÔͨ¹ý·¢ËÍHTTPÇëÇó¹¥»÷WebLogic Server¡£Ò»µ©Ê¹ÓÃÀֳɣ¬±ã¿É½ÓÊÜÄ¿µÄµÄWebLogic Server¡£
¸ÃÎó²îʹÓÃÄѶȽϸߡ£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html¡£
²Î¿¼Á´½Ó
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019verbose-5072833.html


¾©¹«Íø°²±¸11010802024551ºÅ