Apache AxisÔ¶³Ì´úÂëÖ´ÐÐ0day·ì϶´ëÖý¨Òé

°ä²¼¹¦·ò 2019-06-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

ºÏÓÃÓÚApache Axis <= 1.4°æ±¾ £¬Axis ÔÊÐíÔ¶³ÌÖÎÀí £¬Ê¹Óà Freemarker ²å¼þµÄÇé¿öÏ´æÔÚ·ì϶¡£


Ó°ÏìÁìÓò


Ó°ÏìÁìÓò½ÏÓ× £¬¹úÄÚ¶³öÔÚ¹«ÍøµÄAxis £¬²»µ½80¸öip¡£


·ì϶¸ÅÊö


Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷ £¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API £¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓá£


Apache AxisÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶ £¬¹¥»÷Õß¿Éͨ¹ý·¢Ë;«ÐÄ»ú¹ØµÄ¶ñÒâ HTTP-POST ÒªÇó £¬»ñµÃÖ¸±ê·þÎñÆ÷ȨÏÞ £¬ÔÚδÊÚȨÇé¿öÏÂÔ¶³ÌÖ´ÐкÅÁî¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


¹Ù·½ÔÝδ°ä²¼Õë¶Ô´Ë·ì϶µÄ½¨¸´²¹¶¡ £¬ÔÚ¹Ù·½½¨¸´Ö®Ç° £¬Äܹ»²ÉÈ¡ÒÔÏ·½Ê½½øÐÐһʱ·À»¤£º


1¡¢É¾³ýAxis

ÈôÊǵ±Ç°ÏµÍ³²»±ØÒªÊ¹ÓÃAxisµÄÖ°ÄÜ £¬¿ÉÔÚlibĿ¼ÏÂÕÒµ½axis.jarÎļþ £¬½«Æäɾ³ý¡£ÔÚÖ´ÐÐɾ³ý²Ù×÷ǰÇë¶ÔÎļþ×öºÃ±¸·Ý £¬Ô¤·ÀÒòɾ³ýÎļþµ¼ÖµÄÒµÎñÖжÏ¡£


2¡¢½ûÓÃAxisÔ¶³ÌÖÎÀí
µ½ÍøÕ¾Ä¿Â¼ÏÂÕÒµ½server-config.wsddÎļþ £¬ÓÃÎı¾±à×ëÆ÷´ò¿ª £¬ÕÒµ½enableRemoteAdminÅäÖÃÏî £¬½«ÖµÉèÖÃΪfalse £¬ÈçͼËùʾ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾