Adobe ColdFusionÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-28Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-7839£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ColdFusion 2016 update 10ÒÔ¼°Ö®Ç°°æ±¾
ColdFusion 11 update 18ÒÔ¼°Ö®Ç°°æ±¾
Îó²î¸ÅÊö
Adobe ColdFusionÊÇÃÀ¹ú°Â¶à±È£¨Adobe£©¹«Ë¾µÄÒ»Ì׿ìËÙÓ¦ÓóÌÐò¿ª·¢Æ½Ì¨¡£¡£¡£¡£¡£¡£¸Ãƽ̨°üÀ¨¼¯³É¿ª·¢ÇéÐκ;籾ÓïÑÔ¡£¡£¡£¡£¡£¡£
ColdfusionÈí¼þÖб£´æÁ½¸öÑÏÖØÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ÏêϸÈçÏ£º
CVE-2019-7838
¸ÃÎó²îΪÎļþÀ©Õ¹ÃûºÚÃûµ¥ÈƹýÎó²î£¬£¬£¬£¬£¬µ±ÎļþÉÏÔØÄ¿Â¼¿Éͨ¹ýWeb»á¼ûʱ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²î¾ÙÐжñÒâ¹¥»÷£¬£¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
CVE-2019-7839
JNBridgeÊÇÒ»ÖÖ¼¯³ÉJavaºÍ.NETÓ¦ÓóÌÐò´úÂëµÄÊÖÒÕ¡£¡£¡£¡£¡£¡£¸ÃÊÖÒÕͨ¹ýÉè¼ÆÔÊÐí²»ÊÜÏÞÖÆ»á¼ûÔ¶³ÌJavaÔËÐÐʱµÄÇéÐΣ¬£¬£¬£¬£¬´Ó¶øÔÊÐíÖ´ÐÐí§Òâ´úÂëºÍϵͳÏÂÁî¡£¡£¡£¡£¡£¡£
ÔÚWindowsÉÏÔËÐеÄColdfusionЧÀÍÆ÷¹ûÕæJNBridge TCP¶Ë¿Ú6093»ò6095ÉϵÄÍøÂçÕìÌýÆ÷¡£¡£¡£¡£¡£¡£Äܹ»»á¼û¸ÃЧÀ͵Ĺ¥»÷Õß¿ÉÒÔÖ´ÐÐí§Òâ²Ù×÷Java´úÂë»òϵͳÏÂÁî¡£¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬£¬´ËЧÀÍÒÔ×î¸ßȨÏÞ£¨SYSTEM£©ÔËÐС£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýJNBridgeÊÖÒÕ²»ÊÜÏÞÖÆµØ»á¼ûÔ¶³ÌJavaÔËÐÐʱÇéÐΣ¬£¬£¬£¬£¬´Ó¶øÔÊÐíÖ´ÐÐí§Òâ´úÂëºÍϵͳÏÂÁî¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
CVE-2019-7838
ÔÝÎÞPOC/EXP
CVE-2019-7839
EXP:https://cxsecurity.com/issue/WLB-2019060172
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://helpx.adobe.com/security/products/coldfusion/apsb19-27.html
²Î¿¼Á´½Ó
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201906-514


¾©¹«Íø°²±¸11010802024551ºÅ