Weblogic WLS元件REC漏洞(CVE-2017-10271)測試與修復方案

neverinit發表於2018-01-05

本文對“挖礦”漏洞的處理思路是(前提是未被攻擊):

1. 下載工具,測試確認漏洞存在(從Github上下載相關程式)

2. MOS上下載weblogic 補丁修復漏洞

3. 使用工具再次測試漏洞是否存在


第一步,搭建python環境

1.首先訪問去下載windows版的python,這裡下載2.7.14

 
2.下載python2.7安裝包。

3.安裝python

 

點選Next

 

點選Next,這裡可以記一下“C:\Python27\”,後面配置系統環境變數

 

點選“Next”

 

等待安裝完成

點選Finish完成安裝

4. 配置python環境變數,為PATH變數新增引數“C:\Python27\”

 

5.測試python是否安裝成功,開啟cmd命令輸入python

 

執行python命令:print 'Hello World!' 

 

Python環境配置完畢。

第二步,使用工具測試漏洞

1.首先訪問,登陸程式碼託管平臺Github,直接搜尋關鍵字“CVE-2017-10271”

 2.下載hanc00l/weblogic_wls_wsat_rce專案,解壓至F盤(可以測試Linux版本)

 3. 檢視README的內容

  1. weblogic_wls_wsat_rce
  2. Weblogic wls-wsat元件反序列化漏洞(CVE-2017-10271)利用指令碼,參考https://github.com/s3xy/CVE-2017-10271修改。
  • 命令執行並回顯
  • 直接上傳shell
  • 在linux下weblogic 10.3.6.0測試OK
  1. 使用方法及引數
  2. python weblogic_wls_wsat_exp.py -t 172.16.80.131:7001
  3. usage: weblogic_wls_wsat_exp.py [-h] -t TARGET [-c CMD] [-o OUTPUT] [-s SHELL]

  4. optional arguments:
  5.   -h, --help show this help message and exit
  6.   -t TARGET, --target TARGET
  7.                         weblogic ip and port(eg -> 172.16.80.131:7001)
  8.   -c CMD, --cmd CMD command to execute,default is "id"
  9.   -o OUTPUT, --output OUTPUT
  10.                         output file name,default is output.txt
  11.   -s SHELL, --shell SHELL
  12.                         local jsp file name to upload,and set -o xxx.jsp
 4.執行命令測試:python weblogic_wls_wsat_exp.py -t targetip:port
  1. F:\weblogic_wls_wsat_rce-master>python weblogic_wls_wsat_exp.py -t 10.6.3.240:7002 -c ls
  2. Traceback (most recent call last):
  3.   File "F:\CVE-2017-10271-master\weblogic_wls_wsat_exp.py", line 3, in <module>
  4.     import requests
  5. ImportError: No module named requests

根據錯誤資訊,需要安裝requests模組,使用easy_install工具執行命令安裝模組:C:\Python27\Scripts\easy_install.exe requests

  1. F:\weblogic_wls_wsat_rce-master>C:\Python27\Scripts\easy_install.exe requests
  2. Searching for requests
  3. Reading https://pypi.python.org/simple/requests/
  4. Downloading https://pypi.python.org/packages/b0/e1/eab4fc3752e3d240468a8c0b28460
  5. 7899d2fbfb236a56b7377a329aa8d09/requests-2.18.4.tar.gz#md5=081412b2ef79bdc482298
  6. 91af13f4d82
  7. Best match: requests 2.18.4
  8. Processing requests-2.18.4.tar.gz
  9. Writing

  10. ……

  11. Installing chardetect-script.py script to c:\python27\Scripts
  12. Installing chardetect.exe script to c:\python27\Scripts
  13. Installing chardetect.exe.manifest script to c:\python27\Scripts

  14. Installed c:\python27\lib\site-packages\chardet-3.0.4-py2.7.egg
  15. Finished processing dependencies for requests

  16. 再次執行命令
  17. F:\weblogic_wls_wsat_rce-master>python weblogic_wls_wsat_exp.py -t 10.6.3.240:7002 -c ls
  18. autodeploy
  19. bin
  20. config
  21. console-ext
  22. dev=null

顯然,命令執行成功。

第三步,更新補丁修復漏洞

1. 上用關鍵字CVE-2017-10271搜尋,找到2017年10月份的補丁檔案並下載。【p26519424_1036_Generic.zip】

2. 執行打補丁操作(注意:不同的環境和本文的路徑會有所不同)

  1. cams@SCT-APP:~>cd /home/cams/bea/middleware/wlserver_10.3/server/bin/
  2. cams@SCT-APP:~/bea/middleware/wlserver_10.3/server/bin>ls
  3. international setWLSEnv.sh startNodeManager.sh

  4. cams@SCT-APP:~/bea/middleware/wlserver_10.3/server/bin> . ./setWLSEnv.sh
  5. CLASSPATH=/home/cams/bea/middleware/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar:/home/cams/bea/middleware/patch_ocp371/profiles/default/sys_manifest_classpath/weblogic_patch.jar:/usr/java/jdk1.6.0_45/lib/tools.jar:/home/cams/bea/middleware/wlserver_10.3/server/lib/weblogic_sp.jar:/home/cams/bea/middleware/wlserver_10.3/server/lib/weblogic.jar:/home/cams/bea/middleware/modules/features/weblogic.server.modules_10.3.6.0.jar:/home/cams/bea/middleware/wlserver_10.3/server/lib/webservices.jar:/home/cams/bea/middleware/modules/org.apache.ant_1.7.1/lib/ant-all.jar:/home/cams/bea/middleware/modules/net.sf.antcontrib_1.1.0.0_1-0b2/lib/ant-contrib.jar:.:/usr/java/jdk1.6.0_45/lib/dt.jar:/usr/java/jdk1.6.0_45/lib/tools.jar

  6. PATH=/home/cams/bea/middleware/wlserver_10.3/server/bin:/home/cams/bea/middleware/modules/org.apache.ant_1.7.1/bin:/usr/java/jdk1.6.0_45/jre/bin:/usr/java/jdk1.6.0_45/bin:/usr/java/jdk1.6.0_45/bin:/usr/local/bin:/usr/bin:/bin:/usr/bin/X11:/usr/games:

  7. Your environment has been set.

  8. cams@SCT-APP:~/bea/middleware/wlserver_10.3/server/bin> java weblogic.version

  9. WebLogic Server Temporary Patch for BUG22248372 Tue Nov 24 00:35:04 MST 2015
  10. WebLogic Server 10.3.6.0.12 PSU Patch for BUG20780171 THU JUN 18 15:54:42 IST 2015
  11. WebLogic Server 10.3.6.0 Tue Nov 15 08:52:36 PST 2011 1441050

  12. Use 'weblogic.version -verbose' to get subsystem information

  13. Use 'weblogic.utils.Versions' to get version information for all modules
  14. cams@SCT-APP:~/bea/middleware/wlserver_10.3/server/bin> cd /home/cams/bea/middleware/utils/bsu
  15. cams@SCT-APP:~/bea/middleware/utils/bsu> ./bsu.sh -prod_dir=/home/cams/bea/middleware/wlserver_10.3/ -status=applied -verbose -view
  16. ProductName: WebLogic Server
  17. ProductVersion: 10.3 MP6
  18. Components: WebLogic Server/Core Application Server,WebLogic Server/Admi
  19.                    nistration Console,WebLogic Server/Configuration Wizard and
  20.                    Upgrade Framework,WebLogic Server/Web 2.0 HTTP Pub-Sub Serve
  21.                    r,WebLogic Server/WebLogic SCA,WebLogic Server/WebLogic JDBC
  22.                     Drivers,WebLogic Server/Third Party JDBC Drivers,WebLogic S
  23.                    erver/WebLogic Server Clients,WebLogic Server/WebLogic Web S
  24.                    erver Plugins,WebLogic Server/UDDI and Xquery Support,WebLog
  25.                    ic Server/Evaluation Database,WebLogic Server/Workshop Code
  26.                    Completion Support
  27. BEAHome: /home/cams/bea/middleware
  28. ProductHome: /home/cams/bea/middleware/wlserver_10.3
  29. PatchSystemDir: /home/cams/bea/middleware/utils/bsu
  30. PatchDir: /home/cams/bea/middleware/patch_wls1036
  31. Profile: Default
  32. DownloadDir: /home/cams/bea/middleware/utils/bsu/cache_dir
  33. JavaVersion: 1.6.0_29
  34. JavaVendor: Sun


  35. Patch ID: EJUW
  36. PatchContainer: EJUW.jar
  37. Checksum: 1554039558
  38. Severity: optional
  39. Category: General
  40. CR/BUG: 20780171
  41. Restart: true
  42. Description: WLS PATCH SET UPDATE 10.3.6.0.12
  43. WLS PATCH SET UPDATE 10.3.
  44.                    6.0.12

  45. Patch ID: ZLNA
  46. PatchContainer: ZLNA.jar
  47. Checksum: -894774340
  48. Severity: optional
  49. Category: Security
  50. CR/BUG: 22248372
  51. Restart: true
  52. Description: WEBLOGIC SERVER CVE-2015-4852 SECURITY ALERT PATCH (NOV 2015
  53.                    )
  54. WEBLOGIC SERVER CVE-2015-4852 SECURITY ALERT PATCH (NOV 20
  55.                    15)


  56. 上傳p26519424_1036_Generic.zip至DownloadDir:/home/cams/bea/middleware/utils/bsu/cache_dir路徑下,並解壓

  57. cams@SCT-APP:~/bea/middleware/utils/bsu> cd cache_dir/
  58. cams@SCT-APP:~/bea/middleware/utils/bsu/cache_dir> unzip p26519424_1036_Generic.zip
  59. Archive: p26519424_1036_Generic.zip
  60.  extracting: FMJJ.jar
  61.   inflating: patch-catalog_25504.xml
  62. replace README.txt? [y]es, [n]o, [A]ll, [N]one, [r]ename: r
  63. new name: README2.txt
  64.   inflating: README2.txt
  65.   
  66. 如果不知道如何打補丁,參考文章http://blog.itpub.net/31394774/viewspace-2142526/
  67.             
  68. cams@SCT-APP:~/bea/middleware/utils/bsu/cache_dir> cd ../
  69. cams@SCT-APP:~/bea/middleware/utils/bsu> ./bsu.sh -install -patch_download_dir=/home/cams/bea/middleware/utils/bsu/cache_dir/ -patchlist=FMJJ -prod_dir=/home/cams/bea/middleware/wlserver_10.3/ -verbose
  70. 檢查衝突.....
  71. 檢測到衝突 - 解決衝突情形並重新執行補丁程式安裝
  72. 下面是衝突情形詳細資料:
  73. 補丁程式 FMJJ 與以下補丁程式互相排斥且不能共存: EJUW,ZLNA


  74. 此時,需要將EJUW,ZLNA補丁解除安裝,使用-remove命令進行解除安裝。
  75. 【注意:需先解除安裝ZLNA,後解除安裝EJUW】

  76. cams@SCT-APP:~/bea/middleware/utils/bsu> ./bsu.sh -remove -patchlist=EJUW -prod_dir=/home/cams/bea/middleware/wlserver_10.3/ -verbose
  77. 檢查衝突......
  78. 檢測到衝突 - 解決衝突情形並重新執行補丁程式刪除過程
  79. 下面是衝突情形詳細資料:
  80. 必須先刪除下列補丁程式, 才能刪除所選補丁程式: ZLNA

  81. cams@SCT-APP:~/bea/middleware/utils/bsu> ./bsu.sh -remove -patchlist=ZLNA -prod_dir=/home/cams/bea/middleware/wlserver_10.3/ -verbose
  82. 檢查衝突.......
  83. 未檢測到衝突

  84. 開始刪除補丁程式 ID: ZLNA
  85. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlthint3client.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  86. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/BUG22248372_1036.jar
  87. 更新 /home/cams/bea/middleware/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar
  88. 舊清單值: Class-Path= ../../../patch_jars/BUG22248372_1036.jar ../../../patch_jars/BUG20780171_1036012.jar ../../../patch_jars/com.bea.core.apache.commons.fileupload_1.0.0.0_1-3-1.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/glassfish.jaxb.xjc_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxb_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxp_1.4.5.0.jar ../../../patch_jars/glassfish.jaxws.mimepull_1.1.0.0_1-3-8.jar
  89. 新清單值: Class-Path= ../../../patch_jars/BUG22248372_1036.jar ../../../patch_jars/BUG20780171_1036012.jar ../../../patch_jars/com.bea.core.apache.commons.fileupload_1.0.0.0_1-3-1.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/glassfish.jaxb.xjc_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxb_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxp_1.4.5.0.jar ../../../patch_jars/glassfish.jaxws.mimepull_1.1.0.0_1-3-8.jar
  90. 結果: 成功

  91. cams@SCT-APP:~/bea/middleware/utils/bsu> ./bsu.sh -remove -patchlist=EJUW -prod_dir=/home/cams/bea/middleware/wlserver_10.3/ -verbose
  92. 檢查衝突.......
  93. 未檢測到衝突

  94. 開始刪除補丁程式 ID: EJUW
  95. 刪除 /home/cams/bea/middleware/modules/com.bea.core.weblogic.stax_1.11.0.0.jar
  96. 刪除 /home/cams/bea/middleware/wlserver_10.3/bugsfixed/WLS-PSU-bugsfixed.txt
  97. 刪除 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3jmsclient.jar
  98. 刪除 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/APP-INF/lib/commons-io-2.4.jar
  99. 刪除 /home/cams/bea/middleware/wlserver_10.3/bugsfixed/20780171-WLS-10.3.6.0.12_PSU_WebServices-ClientSide-Configuration-README.txt
  100. 刪除 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3client.jar
  101. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/APP-INF/lib/commons-fileupload.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  102. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmxclient.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  103. 還原 /home/cams/bea/middleware/modules/com.oracle.cie.config-wls-schema_10.3.6.0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  104. 還原 /home/cams/bea/middleware/wlserver_10.3/common/wlst/modules/jython-modules.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  105. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlthint3client.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  106. 還原 /home/cams/bea/middleware/wlserver_10.3/common/bin/wlsifconfig.sh 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  107. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlstestclient.ear 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  108. 還原 /home/cams/bea/middleware/modules/com.bea.core.utils.full_1.10.0.0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  109. 還原 /home/cams/bea/middleware/modules/ws.databinding_1.3.0.0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  110. 還原 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml_1.0.0.0_6-2-0-0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  111. 還原 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jsf-2.0.war 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  112. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/schema/weblogic-domain-binding.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  113. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient+ssl.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  114. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmsclient.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  115. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlw-langx.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  116. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsafclient.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  117. 還原 /home/cams/bea/middleware/modules/com.bea.core.apache_1.3.0.1.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  118. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsaft3client.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  119. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.zip 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  120. 還原 /home/cams/bea/middleware/modules/glassfish.jstl_1.2.0.1.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  121. 還原 /home/cams/bea/middleware/modules/com.bea.core.common.security.saml2_1.0.0.0_6-2-0-0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  122. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wls-api.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  123. 還原 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jsf-1.2.war 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  124. 還原 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jstl-1.2.war 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  125. 還原 /home/cams/bea/middleware/modules/com.bea.core.descriptor.wl.binding_1.4.0.0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  126. 還原 /home/cams/bea/middleware/modules/com.oracle.cie.config-wls_7.2.0.0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  127. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/jms-notran-adp.rar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  128. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/jms-xa-adp.rar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  129. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/jdbcdrivers.xml 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  130. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/uddiexplorer.war 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  131. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlclient.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  132. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  133. 還原 /home/cams/bea/middleware/modules/ws.databinding.plugins_1.3.0.0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  134. 還原 /home/cams/bea/middleware/modules/com.bea.core.utils_1.10.0.0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  135. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  136. 還原 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/webapp/WEB-INF/lib/console.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  137. 還原 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml2_1.0.0.0_6-2-0-0.jar 從 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  138. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/BUG20780171_1036012.jar
  139. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/com.bea.core.apache.commons.fileupload_1.0.0.0_1-3-1.jar
  140. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar
  141. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxb.xjc_1.2.0.0_2-1-14.jar
  142. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxb_1.2.0.0_2-1-14.jar
  143. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxp_1.4.5.0.jar
  144. 刪除 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxws.mimepull_1.1.0.0_1-3-8.jar
  145. 更新 /home/cams/bea/middleware/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar
  146. 舊清單值: Class-Path= ../../../patch_jars/BUG20780171_1036012.jar ../../../patch_jars/com.bea.core.apache.commons.fileupload_1.0.0.0_1-3-1.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/glassfish.jaxb.xjc_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxb_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxp_1.4.5.0.jar ../../../patch_jars/glassfish.jaxws.mimepull_1.1.0.0_1-3-8.jar
  147. 新清單值: Class-Path=
  148. 結果: 成功

  149. 再次安裝FMJJ補丁


  150. cams@SCT-APP:~/bea/middleware/utils/bsu> ./bsu.sh -install -patch_download_dir=/home/cams/bea/middleware/utils/bsu/cache_dir/ -patchlist=FMJJ -prod_dir=/home/cams/bea/middleware/wlserver_10.3/ -verbose
  151. 檢查衝突.....
  152. 未檢測到衝突

  153. 開始安裝補丁程式 ID: FMJJ
  154. 安裝 /home/cams/bea/middleware/utils/bsu/cache_dir/FMJJ.jar
  155. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/BUG26519424_10360171017.jar
  156. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/com.bea.core.apache.commons.fileupload_1.0.0.0_1-3-1.jar
  157. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar
  158. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxb.xjc_1.2.0.0_2-1-14.jar
  159. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxb_1.2.0.0_2-1-14.jar
  160. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxp_1.4.5.0.jar
  161. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxws.mimepull_1.1.0.0_1-3-8.jar
  162. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxws.rt_1.4.0.0_2-1-5.jar
  163. 解壓縮 /home/cams/bea/middleware/patch_wls1036/patch_jars/glassfish.jaxws.saaj.impl_1.0.0.0_2-1-5.jar
  164. 更新 /home/cams/bea/middleware/patch_wls1036/profiles/default/sys_manifest_classpath/weblogic_patch.jar
  165. 舊清單值: Class-Path=
  166. 新清單值: Class-Path=../../../patch_jars/BUG26519424_10360171017.jar ../../../patch_jars/com.bea.core.apache.commons.fileupload_1.0.0.0_1-3-1.jar ../../../patch_jars/com.bea.core.stax2_2.0.0.0_3-0-3.jar ../../../patch_jars/glassfish.jaxb.xjc_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxb_1.2.0.0_2-1-14.jar ../../../patch_jars/glassfish.jaxp_1.4.5.0.jar ../../../patch_jars/glassfish.jaxws.mimepull_1.1.0.0_1-3-8.jar ../../../patch_jars/glassfish.jaxws.rt_1.4.0.0_2-1-5.jar ../../../patch_jars/glassfish.jaxws.saaj.impl_1.0.0.0_2-1-5.jar
  167. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/DefaultAuthorizerInit.ldift 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  168. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlstestclient.ear 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  169. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/jms-notran-adp.rar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  170. 備份 /home/cams/bea/middleware/modules/com.oracle.cie.config-wls-schema_10.3.6.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  171. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/XACMLAuthorizerInit.ldift 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  172. 備份 /home/cams/bea/middleware/wlserver_10.3/common/bin/wlsifconfig.sh 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  173. 備份 /home/cams/bea/middleware/modules/com.bea.core.descriptor.wl_1.4.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  174. 備份 /home/cams/bea/middleware/modules/javax.jsf_1.1.0.0_1-2.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  175. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/schema/weblogic-domain-binding.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  176. 備份 /home/cams/bea/middleware/modules/com.bea.core.apache.commons.io_1.0.0.0_1-4.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  177. 備份 /home/cams/bea/middleware/modules/com.bea.core.apache.xalan_2.7.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  178. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/webapp/WEB-INF/lib/console.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  179. 備份 /home/cams/bea/middleware/modules/com.bea.core.descriptor.wl.binding_1.4.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  180. 備份 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jstl-1.2.war 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  181. 備份 /home/cams/bea/middleware/wlserver_10.3/common/templates/domains/wls.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  182. 備份 /home/cams/bea/middleware/wlserver_10.3/common/wlst/modules/jython-modules.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  183. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/APP-INF/lib/commons-fileupload.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  184. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlthint3client.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  185. 備份 /home/cams/bea/middleware/modules/com.bea.core.apache.commons.collections_3.2.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  186. 備份 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jsf-1.2.war 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  187. 備份 /home/cams/bea/middleware/modules/com.oracle.cie.config-wls_7.2.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  188. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlclient.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  189. 備份 /home/cams/bea/middleware/modules/glassfish.jstl_1.2.0.1.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  190. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  191. 備份 /home/cams/bea/middleware/modules/com.bea.core.descriptor.wl.ja_1.4.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  192. 備份 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jsf-2.0.war 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  193. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient+ssl.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  194. 備份 /home/cams/bea/middleware/modules/com.bea.core.apache.xml.serializer_2.7.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  195. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/jms-xa-adp.rar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  196. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/jdbcdrivers.xml 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  197. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/DefaultAuthorizerInit.ldift
  198. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlstestclient.ear
  199. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/jms-notran-adp.rar
  200. 解壓縮 /home/cams/bea/middleware/modules/com.oracle.cie.config-wls-schema_10.3.6.0.jar
  201. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/APP-INF/lib/commons-io-2.4.jar
  202. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/XACMLAuthorizerInit.ldift
  203. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/common/bin/wlsifconfig.sh
  204. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/bugsfixed/26519424-WLS-10.3.6.0.171017_PSU_WebServices-ClientSide-Configuration-README.txt
  205. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/bugsfixed/WLS-PSU-bugsfixed.txt
  206. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.descriptor.wl_1.4.0.0.jar
  207. 解壓縮 /home/cams/bea/middleware/modules/javax.jsf_1.1.0.0_1-2.jar
  208. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/schema/weblogic-domain-binding.jar
  209. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.apache.commons.io_1.0.0.0_1-4.jar
  210. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.apache.xalan_2.7.0.jar
  211. 解壓縮 /home/cams/bea/middleware/modules/glassfish.jsf_1.0.0.0_1-2-15.jar
  212. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/webapp/WEB-INF/lib/console.jar
  213. 解壓縮 /home/cams/bea/middleware/modules/javax.jsf_1.0.0.0_2-0.jar
  214. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.descriptor.wl.binding_1.4.0.0.jar
  215. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jstl-1.2.war
  216. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/common/templates/domains/wls.jar
  217. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/common/wlst/modules/jython-modules.jar
  218. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/consoleapp/APP-INF/lib/commons-fileupload.jar
  219. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlthint3client.jar
  220. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/XACMLAuthorizerUpdate_62.ldift
  221. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.apache.commons.collections_3.2.0.jar
  222. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jsf-1.2.war
  223. 解壓縮 /home/cams/bea/middleware/modules/com.oracle.cie.config-wls_7.2.0.0.jar
  224. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlclient.jar
  225. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.stax2_2.0.0.0_3-0-3.jar
  226. 解壓縮 /home/cams/bea/middleware/modules/glassfish.jstl_1.2.0.1.jar
  227. 解壓縮 /home/cams/bea/middleware/modules/glassfish.jsf_1.0.0.0_2-0-4.jar
  228. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.jar
  229. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.descriptor.wl.ja_1.4.0.0.jar
  230. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/common/deployable-libraries/jsf-2.0.war
  231. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/DefaultAuthorizerUpdate_62.ldift
  232. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient+ssl.jar
  233. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.apache.xml.serializer_2.7.0.jar
  234. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/jms-xa-adp.rar
  235. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/jdbcdrivers.xml
  236. 備份 /home/cams/bea/middleware/modules/com.oracle.core.coherence.integration_1.2.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  237. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wls-api.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  238. 備份 /home/cams/bea/middleware/modules/com.bea.core.common.security.impl_1.0.0.0_6-2-0-0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  239. 備份 /home/cams/bea/middleware/modules/com.bea.core.weblogic.security.wls_1.0.0.0_6-2-0-0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  240. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.zip 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  241. 備份 /home/cams/bea/middleware/modules/ws.databinding_1.3.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  242. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/uddiexplorer.war 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  243. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  244. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsafclient.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  245. 備份 /home/cams/bea/middleware/modules/com.bea.core.apache_1.3.0.1.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  246. 備份 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml_1.0.0.0_6-2-0-0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  247. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlw-langx.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  248. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmxclient.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  249. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsaft3client.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  250. 備份 /home/cams/bea/middleware/modules/ws.databinding.plugins_1.3.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  251. 備份 /home/cams/bea/middleware/modules/com.oracle.core.weblogic.msgcat_1.2.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  252. 備份 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml2_1.0.0.0_6-2-0-0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  253. 備份 /home/cams/bea/middleware/modules/com.bea.core.descriptor_1.10.0.0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  254. 備份 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmsclient.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  255. 備份 /home/cams/bea/middleware/modules/com.bea.core.common.security.saml2_1.0.0.0_6-2-0-0.jar 至 /home/cams/bea/middleware/patch_wls1036/backup/backup.jar
  256. 解壓縮 /home/cams/bea/middleware/modules/com.oracle.core.coherence.integration_1.2.0.0.jar52609.tmp
  257. 合併 /home/cams/bea/middleware/modules/com.oracle.core.coherence.integration_1.2.0.0.jar52609.tmp 與 /home/cams/bea/middleware/modules/com.oracle.core.coherence.integration_1.2.0.0.jar
  258. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wls-api.jar22088.tmp
  259. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/wls-api.jar22088.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/wls-api.jar
  260. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.common.security.impl_1.0.0.0_6-2-0-0.jar46334.tmp
  261. 合併 /home/cams/bea/middleware/modules/com.bea.core.common.security.impl_1.0.0.0_6-2-0-0.jar46334.tmp 與 /home/cams/bea/middleware/modules/com.bea.core.common.security.impl_1.0.0.0_6-2-0-0.jar
  262. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.weblogic.security.wls_1.0.0.0_6-2-0-0.jar57180.tmp
  263. 合併 /home/cams/bea/middleware/modules/com.bea.core.weblogic.security.wls_1.0.0.0_6-2-0-0.jar57180.tmp 與 /home/cams/bea/middleware/modules/com.bea.core.weblogic.security.wls_1.0.0.0_6-2-0-0.jar
  264. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.zip61185.tmp
  265. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.zip61185.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/wseeclient.zip
  266. 解壓縮 /home/cams/bea/middleware/modules/ws.databinding_1.3.0.0.jar30164.tmp
  267. 合併 /home/cams/bea/middleware/modules/ws.databinding_1.3.0.0.jar30164.tmp 與 /home/cams/bea/middleware/modules/ws.databinding_1.3.0.0.jar
  268. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/uddiexplorer.war61491.tmp
  269. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/uddiexplorer.war61491.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/uddiexplorer.war
  270. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient.jar25254.tmp
  271. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient.jar25254.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/webserviceclient.jar
  272. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsafclient.jar35800.tmp
  273. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsafclient.jar35800.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsafclient.jar
  274. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.apache_1.3.0.1.jar63015.tmp
  275. 合併 /home/cams/bea/middleware/modules/com.bea.core.apache_1.3.0.1.jar63015.tmp 與 /home/cams/bea/middleware/modules/com.bea.core.apache_1.3.0.1.jar
  276. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml_1.0.0.0_6-2-0-0.jar1609.tmp
  277. 合併 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml_1.0.0.0_6-2-0-0.jar1609.tmp 與 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml_1.0.0.0_6-2-0-0.jar
  278. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3client.jar33270.tmp
  279. 更新 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3client.jar33270.tmp 到 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3client.jar
  280. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlw-langx.jar15576.tmp
  281. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlw-langx.jar15576.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlw-langx.jar
  282. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3jmsclient.jar29013.tmp
  283. 更新 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3jmsclient.jar29013.tmp 到 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlt3jmsclient.jar
  284. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmxclient.jar43506.tmp
  285. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmxclient.jar43506.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmxclient.jar
  286. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsaft3client.jar43891.tmp
  287. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsaft3client.jar43891.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/wlsaft3client.jar
  288. 解壓縮 /home/cams/bea/middleware/modules/ws.databinding.plugins_1.3.0.0.jar16566.tmp
  289. 合併 /home/cams/bea/middleware/modules/ws.databinding.plugins_1.3.0.0.jar16566.tmp 與 /home/cams/bea/middleware/modules/ws.databinding.plugins_1.3.0.0.jar
  290. 解壓縮 /home/cams/bea/middleware/modules/com.oracle.core.weblogic.msgcat_1.2.0.0.jar32086.tmp
  291. 合併 /home/cams/bea/middleware/modules/com.oracle.core.weblogic.msgcat_1.2.0.0.jar32086.tmp 與 /home/cams/bea/middleware/modules/com.oracle.core.weblogic.msgcat_1.2.0.0.jar
  292. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml2_1.0.0.0_6-2-0-0.jar34414.tmp
  293. 合併 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml2_1.0.0.0_6-2-0-0.jar34414.tmp 與 /home/cams/bea/middleware/modules/com.bea.core.bea.opensaml2_1.0.0.0_6-2-0-0.jar
  294. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.descriptor_1.10.0.0.jar20553.tmp
  295. 合併 /home/cams/bea/middleware/modules/com.bea.core.descriptor_1.10.0.0.jar20553.tmp 與 /home/cams/bea/middleware/modules/com.bea.core.descriptor_1.10.0.0.jar
  296. 解壓縮 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmsclient.jar52216.tmp
  297. 合併 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmsclient.jar52216.tmp 與 /home/cams/bea/middleware/wlserver_10.3/server/lib/wljmsclient.jar
  298. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.common.security.saml2_1.0.0.0_6-2-0-0.jar55023.tmp
  299. 合併 /home/cams/bea/middleware/modules/com.bea.core.common.security.saml2_1.0.0.0_6-2-0-0.jar55023.tmp 與 /home/cams/bea/middleware/modules/com.bea.core.common.security.saml2_1.0.0.0_6-2-0-0.jar
  300. 解壓縮 /home/cams/bea/middleware/modules/com.bea.core.weblogic.stax_1.11.0.0.jar45419.tmp
  301. 更新 /home/cams/bea/middleware/modules/com.bea.core.weblogic.stax_1.11.0.0.jar45419.tmp 到 /home/cams/bea/middleware/modules/com.bea.core.weblogic.stax_1.11.0.0.jar
  302. 結果: 成功
3. 檢視最新的補丁資訊


  1. cams@SCT-APP:~/bea/middleware/utils/bsu> ./bsu.sh -prod_dir=/home/cams/bea/middleware/wlserver_10.3/ -status=applied -verbose -view
  2. ProductName: WebLogic Server
  3. ProductVersion: 10.3 MP6
  4. Components: WebLogic Server/Core Application Server,WebLogic Server/Admi
  5.                    nistration Console,WebLogic Server/Configuration Wizard and
  6.                    Upgrade Framework,WebLogic Server/Web 2.0 HTTP Pub-Sub Serve
  7.                    r,WebLogic Server/WebLogic SCA,WebLogic Server/WebLogic JDBC
  8.                     Drivers,WebLogic Server/Third Party JDBC Drivers,WebLogic S
  9.                    erver/WebLogic Server Clients,WebLogic Server/WebLogic Web S
  10.                    erver Plugins,WebLogic Server/UDDI and Xquery Support,WebLog
  11.                    ic Server/Evaluation Database,WebLogic Server/Workshop Code
  12.                    Completion Support
  13. BEAHome: /home/cams/bea/middleware
  14. ProductHome: /home/cams/bea/middleware/wlserver_10.3
  15. PatchSystemDir: /home/cams/bea/middleware/utils/bsu
  16. PatchDir: /home/cams/bea/middleware/patch_wls1036
  17. Profile: Default
  18. DownloadDir: /home/cams/bea/middleware/utils/bsu/cache_dir
  19. JavaVersion: 1.6.0_29
  20. JavaVendor: Sun


  21. Patch ID: FMJJ
  22. PatchContainer: FMJJ.jar
  23. Checksum: 591477727
  24. Severity: optional
  25. Category: General
  26. CR/BUG: 26519424
  27. Restart: true
  28. Description: WLS PATCH SET UPDATE 10.3.6.0.171017
  29. WLS PATCH SET UPDATE 10
  30.                    .3.6.0.171017


第四步,使用工具複測漏洞

1. 啟動一個weblogic

  1. cams@SCT-APP:~/bea/middleware/utils/bsu> cd /home/cams/bea/middleware/user_projects/domains/cams_wf/
  2. cams@SCT-APP:~/bea/middleware/user_projects/domains/cams_wf> nohup ./startWebLogic.sh >/dev/null 2>&1 &
  3. [1] 17849
  4. cams@SCT-APP:~/bea/middleware/user_projects/domains/cams_wfnetstat -nlp | grep 7006
  5. (Not all processes could be identified, non-owned process info
  6.  will not be shown, you would have to be root to see it all.)
  7. tcp 0 0 10.6.3.226:7006 0.0.0.0:* LISTEN 17902/java
  8. tcp 0 0 127.0.0.1:7006 0.0.0.0:* LISTEN 17902/java
2.測試RCE漏洞
  1. F:\weblogic_wls_wsat_rce-master>python weblogic_wls_wsat_exp.py -t 10.6.3.226:70
  2. 06 -c ls
  3. [-]FAIL:404 no output
從測試返回結果“FAIL:404 no output”,顯然漏洞已經修復。
3.最後,由於之前操作解除安裝了反序列化漏洞的補丁,還需使用測試“Java反序列化漏洞”是否存在。經過測試,反序列化漏洞也已經修復。(具體測試工具也可從Github上下載)


來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/31394774/viewspace-2149752/,如需轉載,請註明出處,否則將追究法律責任。

相關文章