¡¾Ô´´Îó²î¡¿WebLogic Blind XXEÎó²î£¨CVE-2019-2647£©
Ðû²¼Ê±¼ä 2019-04-17Îó²îȪԴ£ºc7c7ÓéÀÖÆ½Ì¨ADLab
Ðû²¼Ê±¼ä£º2019Äê4ÔÂ17ÈÕ
Îó²î¸ÅÊö
2019Äê4ÔÂ17ÈÕ£¬£¬£¬£¬Oracle¹Ù·½Ðû²¼4Ô·ÝÇå¾²²¹¶¡, ²¹¶¡ÖаüÀ¨c7c7ÓéÀÖÆ½Ì¨ADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸øOracle¹Ù·½µÄWebLogic Blind XXEÎó²î£¬£¬£¬£¬Îó²î±àºÅΪCVE-2019-2647¡£¡£¡£Ê¹ÓøÃÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ÐÒéÖУ¬£¬£¬£¬Í¨¹ý¶ÔT3ÐÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£
Îó²îʱ¼äÖá
2019Äê1ÔÂ17ÈÕ£ºÈ·ÈÏÎó²î±£´æ²¢×îÏÈÐÞ¸´£»£»£»
2019Äê4ÔÂ17ÈÕ£ºOracle¹Ù·½Ðû²¼Çå¾²²¹¶¡¡£¡£¡£
Ó°Ïì°æ±¾
WebLogic 12.1.3.0
WebLogic 12.2.1.2
WebLogic 12.2.1.3
Îó²îʹÓÃ
²âÊÔÇéÐΣºWebLogic Server 10.3.6.0£¨´ò²¹p28343311_1036_Generic£©
¹æ±Ü¼Æ»®
1¡¢Éý¼¶²¹¶¡
Oracle¹Ù·½¸üÐÂÁ´½ÓµØµã£ºhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html ¡£¡£¡£
2¡¢¿ØÖÆT3ÐÒéµÄ»á¼û
WebLogic Blind XXEÎó²î±¬·¢ÓÚWebLogicµÄT3ЧÀÍ£¬£¬£¬£¬Òò´Ë¿Éͨ¹ý¿ØÖÆT3ÐÒéµÄ»á¼ûÀ´ÔÝʱ×è¶ÏÕë¶Ô¸ÃÎó²îµÄ¹¥»÷¡£¡£¡£µ±¿ª·ÅWebLogic¿ØÖÆÌ¨¶Ë¿Ú£¨Ä¬ÒÔΪ7001¶Ë¿Ú£©Ê±£¬£¬£¬£¬T3ЧÀÍ»áĬÈÏ¿ªÆô¡£¡£¡£
Ïêϸ²Ù×÷£º
£¨1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£
£¨2£©ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3 t3s£¬£¬£¬£¬0.0.0.0/0 * * deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ