Oracle iPlanet Web Server | 多个清静误差通告
宣布时间 2020-05-120x00 误差概述
|
产品 |
CVE ID |
类 型 |
误差品级 |
远程使用 |
影响规模 |
|
Oracle iPlanet Web Server |
CVE-2020-9314 |
I |
中危 |
是 |
Oracle iPlanet Web Server 7.0.x版本 |
|
CVE-2020-9315 |
|
中危 |
是 |
0x01 误差详情
Oracle iPlanet Web Server(OiWS)是美国甲骨文(Oracle)公司的一款主要用于中型和大型营业应用程序的Web服务器。
最近,研究职员发明了两个影响Oracle iPlanet Web Server的清静误差,跟踪到的误差为CVE-2020-9314和CVE-2020-9315,它们可能导致注入攻击和敏感数据泄露。
CVE-2020-9314是Oracle iPlanet Web Server的Web管理控制台中保存的一个注入误差。管理控制台中的“productNameSrc”参数允许注入外部映像。当与“productNameHeight”和“productNameWidth”参数团结使用时,可以将外部图像注入站点以利于网络垂纶。这是由于CVE-2012-0516的修补程序不完整所致。较早的修复程序添加了针对XSS问题的验证,但对确保没有加载外部映像未添加验证。
误差验证可实验以下链接:
http://%5Btarget%5D/admingui/version/Version?&productNameSrc=http://www.example.com/test.jpg&productNameHeight=500&productNameWidth=500
http://%5Btarget%5D/admingui/version/Masthead.jsp?productNameSrc=http://www.example.com/test.jpg&productNameHeight=500&productNameWidth=500
CVE-2020-9315是Oracle iPlanet Web Server的Web管理控制台中保存的一个清静误差。该误差使得无需身份验证即可从控制台中的任何页面读守信息。这可能导致有关服务器的设置信息(包括加密密钥,JVM设置和其他数据)的敏感数据泄露�?梢酝ü婊还芾砜刂铺ㄖ腥魏我趁娴娜魏蜺RL来完成,如下所示:
http://%5Btarget%5D/admingui/admingui/*
http://%5Btarget%5D/admingui/版本/*
误差验证可实验以下链接:
http://%5Btarget%5D/admingui/version/
http://%5Btarget%5D/admingui/version/serverTasksGeneral?serverTasksGeneral.GeneralWebserverTabs.Tabhref=2
0x02 处置惩罚建议
由于Oracle不再支持Oracle iPlanet Web Server 7.0.x,以是不妄想宣布清静补丁程序。
暂时步伐:
最新版本的Oracle Glassfish和Eclipse Glassfish与iPlanet共享通用代码,已通过测试,没有误差,建议受影响用户下载使用。
限制从Internet到Oracle iPlanet Web Server的Web管理控制台的会见,只允允许信ip会见。
0x03 相关新闻
https://securityaffairs.co/wordpress/103055/hacking/oracles-iplanet-web-server-flaws.html?utm_source=rss&utm_medium=rss&utm_campaign=oracles-iplanet-web-server-flaws
0x04 参考链接
https://wwws.nightwatchcybersecurity.com/2020/05/10/two-vulnerabilities-in-oracles-iplanet-web-server-cve-2020-9315-and-cve-2020-9314/
https://www.oracle.com/us/assets/lifetime-support-middleware-069163.pdf
0x05 时间线
2020-05-12 VSRC宣布误差通告


京公网安备11010802024551号