Apache AxisÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²î´¦Öóͷ£½¨Òé

Ðû²¼Ê±¼ä 2019-06-19

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

ÊÊÓÃÓÚApache Axis <= 1.4°æ±¾£¬Axis ÔÊÐíÔ¶³Ì¹ÜÀí£¬Ê¹Óà Freemarker ²å¼þµÄÇéÐÎϱ£´æÎó²î¡£


Ó°Ïì¹æÄ£


Ó°Ïì¹æÄ£½ÏС£¬º£ÄÚ̻¶ÔÚ¹«ÍøµÄAxis£¬²»µ½80¸öip¡£


Îó²î¸ÅÊö


Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API£¬ÒÔÌìÉúºÍ°²ÅÅWeb·þÎñÓ¦Óá£


Apache AxisÖб£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÈ«ÐĽṹµÄ¶ñÒâ HTTP-POST ÇëÇ󣬻ñµÃÄ¿µÄ·þÎñÆ÷ȨÏÞ£¬ÔÚδÊÚȨÇéÐÎÏÂÔ¶³ÌÖ´ÐÐÏÂÁî¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


¹Ù·½ÔÝδÐû²¼Õë¶Ô´ËÎó²îµÄÐÞ¸´²¹¶¡£¬ÔÚ¹Ù·½ÐÞ¸´Ö®Ç°£¬¿ÉÒÔ½ÓÄÉÒÔÏ·½·¨¾ÙÐÐÔÝʱ·À»¤£º


1¡¢É¾³ýAxis

ÈôÊÇÄ¿½ñϵͳ²»ÐèҪʹÓÃAxisµÄ¹¦Ð§£¬¿ÉÔÚlibĿ¼ÏÂÕÒµ½axis.jarÎļþ£¬½«Æäɾ³ý¡£ÔÚÖ´ÐÐɾ³ý²Ù×÷ǰÇë¶ÔÎļþ×öºÃ±¸·Ý£¬±ÜÃâÒòɾ³ýÎļþµ¼ÖµÄÓªÒµÖÐÖ¹¡£


2¡¢½ûÓÃAxisÔ¶³Ì¹ÜÀí
µ½ÍøÕ¾Ä¿Â¼ÏÂÕÒµ½server-config.wsddÎļþ£¬ÓÃÎı¾±à¼­Æ÷·­¿ª£¬ÕÒµ½enableRemoteAdminÉèÖÃÏ½«ÖµÉèÖÃΪfalse£¬ÈçͼËùʾ£º

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£