Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-2556 PoC — Oracle Construction and Engineering Suite 安全漏洞

Source
Associated Vulnerability
Title: Oracle Construction and Engineering Suite 安全漏洞 (CVE-2020-2556)
Description:Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Core). Supported versions that are affected are 16.2.0.0-16.2.19.0, 17.12.0.0-17.12.16.0, 18.8.0.0-18.8.16.0, 19.12.0.0 and 20.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Primavera P6 Enterprise Project Portfolio Management executes to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L).
Description
CVE-2020-2555
Readme
# CVE-2020-2555
## 概述

在2020年1月,互联网上爆出了Weblogic反序列化远程命令执行漏洞(CVE-2020-2555),Oracle Fusion中间件Oracle Coherence存在缺陷,攻击者可利用该漏洞在未经授权下通过构造T3协议请求,获取Weblogic服务器权限,执行任意命令,风险较大。

## 影响

Oracle Coherence 3.7.1.17

Oracle Coherence & Weblogic  12.1.3.0.0

Oracle Coherence & Weblogic 12.2.1.3.0

Oracle Coherence & Weblogic 12.2.1.4.0

## 复现

![](https://img.zhiiyun.com/blog_2c795b06cae4deaec7a9e1a2e7a70846)



PDF 版本:[漫谈-Weblogic-CVE-2020-2555.pdf](./漫谈-Weblogic-CVE-2020-2555.pdf)

在线版本:[漫谈 Weblogic CVE-2020-2555](https://www.r4v3zn.com/posts/975312a1/)

### 测试 POC 版本



| 版本       | 文件名                                                | 描述    | 操作系统 |
| ---------- | ----------------------------------------------------- | ------- | -------- |
| 12.1.3.0.0 | [121300_calc.666](./file/121300_calc.666)             | calc    | Windows  |
| 12.1.3.0.0 | [121300_notepad.666](./file/121300_notepad.666)       | notepad | Windows  |
| 12.1.3.0.0 | [121300_ping.666](./file/121300_ping.666)             | ping    | Windows  |
| 12.1.3.0.0 | [121300.666](./file/121300.666)                       | calc    | Windows  |
| 12.2.1.3.0 | [122130_calc.666](./file/122130_calc.666)             | calc    | Windows  |
| 12.2.1.3.0 | [122130_linux_calc.666](./file/122130_linux_calc.666) | calc    | Linux    |
| 12.2.1.3.0 | [122130_linux_curl.666](./file/122130_linux_curl.666) | curl    | Linux    |
| 12.2.1.3.0 | [122130_notepad.666](./file/122130_notepad.666)       | notepad | Windows  |
| 12.2.1.3.0 | [122130.666](./file/122130.666)                       | calc    | Windows  |
| 12.2.1.4.0 | [122140_calc.666](./file/122140_calc.666)             | calc    | Windows  |
| 12.2.1.4.0 | [122140_linux_calc.666](./file/122140_linux_calc.666) | calc    | Linux    |
| 12.2.1.4.0 | [122140_linux_curl.666](./file/122140_linux_curl.666) | curl    | Linux    |
| 12.2.1.4.0 | [122140_notepad.666](./file/122140_notepad.666)       | notepad | Windows  |
| 12.2.1.4.0 | [122140.666](./file/122140.666)                       | calc    | Windows  |



## 修复建议

Oracle官方补丁需要登录帐户后下载([https://login.oracle.com)](https://login.oracle.com/)

官方介绍:https://www.oracle.com/security-alerts/cpujan2020.html

也可以通过临时禁用T3协议来防御攻击。

## 参考

- [CVE-2020-2555:WebLogic远程代码执行漏洞](https://nosec.org/home/detail/4205.html)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →