关于NCC LoggingConfigServlet反序列化漏洞的公告
漏洞概述
关于NCC LoggingConfigServlet反序列化漏洞的解决方案
用友NCC LoggingConfigServlet反序列化高危漏洞可获取服务器权限,漏洞地址http://x.x.x.x/servlet/~nc.bs.logging.config.LoggingConfigServlet[post],用友存在反序列化漏洞,攻击者可以利用该漏洞结合任意文件写入利用链实现上传文件,对服务器造成破坏。用友总部紧急提供对应各个版本解决方案。请一线机构务必高度重视,各机构高端客户成功总监负责所属机构所有项目,及时为所属机构客户进行安装,规避项目风险。
影响版本:NC55 NC56 NC57 NC63 NC633 NC65 NCC1903 NCC1909 NCC2005 NCC2105 NCC2111
解决方案:
NC55日志配置Servlet反序列化安全补丁
NCM_NC5.5_000_1008_20220805_GP_676640668
https://dsp.yonyou.com/patchcenter/patchdetail/11221659676641606320/0/2
NC56日志配置Servlet反序列化安全补丁
NCM_NC5.6_000_1008_20220804_GP_627529619
https://dsp.yonyou.com/patchcenter/patchdetail/11221659627530505111/0/2
NC57日志配置Servlet反序列化安全补丁
NCM_NC5.7_000_109902_20220804_GP_627576685
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627577669430/0/2
NC63日志配置Servlet反序列化安全补丁
NCM_NC6.3_000_109902_20220804_GP_627596817
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627597758437/0/2
NC633日志配置Servlet反序列化安全补丁
NCM_NC6.33_000_109902_20220804_GP_627715474
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627716376444/0/2
NC65日志配置Servlet反序列化安全补丁
NCM_NC6.5_000_109902_20220804_GP_627640856
https://dsp.yonyou.com/patchcenter/patchdetail/11221659627641766118/0/2
NCC1903日志配置Servlet反序列化安全补丁
NCM_NCCLOUD1903_10_109902_20220804_GP_627758190
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627759041451/0/2
NCC1909日志配置Servlet反序列化安全补丁
NCM_NCCLOUD1909_10_109902_20220804_GP_627788883
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627789725458/0/2
NCC2005日志配置Servlet反序列化安全补丁
NCM_NCCLOUD2020.05_10_109902_20220804_GP_627807614
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627808492465/0/2
NCC2105日志配置Servlet反序列化安全补丁
NCM_NCCLOUD2021.05_10_0013_20220804_GP_627833564
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627834433472/0/2
NCC2111日志配置Servlet反序列化安全补丁
NCM_NCCLOUD2021.11_010_0013_20220804_GP_627853382
https://dsp.yonyou.com/patchcenter/patchdetail/10221659627854268479/0/2
《安全补丁检查工具》云巡检版本也同步支持对该漏洞的检测和修复功能(建议方式),云巡检工具部署详见云盘链接:
https://pan.yonyou.com/s/v5fT9oUPR9s 密码:hyvt
漏洞得分
更新时间
补丁下载:
https://www.iufida.com/126-136727-0.html
https://www.iufida.com/126-136729-0.html
本站不提供下载资料的技术支持。使用者必须具备技术能力并自行解决问题!否则请勿下载。