Oracle 4Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-04-21

0x00 ©¶´¸ÅÊö

2021Äê04ÔÂ20ÈÕ£¬OracleÐû²¼ÁË4Ô·ݵÄÄþ¾²¸üУ¬±¾´ÎÐû²¼µÄÄþ¾²²¹¶¡¹²¼Æ390¸ö£¬Éæ¼°Oracle Fusion Middleware¡¢Oracle E-Business Suite¡¢Oracle Communications ApplicationsºÍOracle MySQLµÈ¶à¸ö²úÎïºÍ×é¼þ¡£

 

0x01 ©¶´ÏêÇé

image.png

 

ÔÚ±¾´ÎÐû²¼µÄÄþ¾²²¹¶¡ÖУ¬Oracle Fusion MiddlewareÏà¹ØµÄ²¹¶¡Îª45¸ö£¬ÆäÖÐ36¸ö©¶´ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£Weblogic Server²¿ÃÅ©¶´ÏêÇéÈçÏ£º

Oracle WebLogic Server Coherence ContainerÄþ¾²Â©¶´£¨CVE-2021-2135£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýT3»òIIOPЭÒé·¢ËͶñÒâÇëÇó£¬×îÖÕ¿ØÖÆ·þÎñÆ÷¡£¸Ã©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÆäCVSSÆÀ·ÖΪ9.8¡£

Ó°Ï췶Χ

12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0

 

Oracle WebLogic Server CoreÄþ¾²Â©¶´£¨CVE-2021-2136£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPЭÒé·¢ËͶñÒâÇëÇó£¬×îÖÕ¿ØÖÆ·þÎñÆ÷¡£¸Ã©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÆäCVSSÆÀ·ÖΪ9.8¡£

Ó°Ï췶Χ

12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0

 

Oracle WebLogic Server TopLink IntegrationÄþ¾²Â©¶´£¨CVE-2021-2157£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýHTTP·¢ËͶñÒâÇëÇó£¬×îÖÕ¿ÉÒÔδÊÚȨ·ÃÎÊÒªº¦Êý¾Ý¡£¸Ã©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÆäCVSSÆÀ·ÖΪ7.5¡£

Ó°Ï췶Χ

10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0

 

´ËÍ⣬ÔÚOracle±¾´ÎÐû²¼µÄÄþ¾²²¹¶¡ÖУº

ÓëOracle Communications ApplicationsÏà¹ØµÄ²¹¶¡Îª13¸ö£¬ÆäÖÐCVE-2020-11612ºÍCVE-2020-28052ÆÀ·ÖΪ9.8£¬¹¥»÷ÕßÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓðüÂÞÕâ2¸ö©¶´ÔÚÄÚµÄ12¸öÄþ¾²Â©¶´¡£

ÓëE-Business SuiteÏà¹ØµÄ²¹¶¡Îª70¸ö£¬ÆäÖÐCVE-2021-2200ºÍCVE-2021-2205ÆÀ·ÖΪ9.1£¬¹¥»÷ÕßÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓðüÂÞÕâ2¸ö©¶´ÔÚÄÚµÄ22¸öÄþ¾²Â©¶´¡£

ÓëOracle MySQLÏà¹ØµÄ²¹¶¡Îª49¸ö£¬ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓõÄ©¶´Îª10¸ö£¬ÆäÖÐCVE-2021-3449ºÍCVE-2021-3450£¨¾ùΪMySQL ServerÖеÄOpenSSLÎÊÌ⣩ÆÀ·Ö·Ö±ðΪ7.5ºÍ7.4, CVE-2021-2307ΪMySQL for WindowsÖеÄȨÏÞÌáÉý©¶´£¬¸Ã©¶´Ðè¾­¹ýÑéÖ¤²ÅÆøÀûÓã¬ÆäCVSSÆÀ·ÖΪ6.1¡£

 

0x02 ´¦Öý¨Òé

ĿǰOracleÒѾ­Ðû²¼Ïà¹ØÄþ¾²²¹¶¡£¬½¨Ò龡¿ìÓ¦Óá£

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2021.html

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuapr2021.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2135

https://kb.cert.org/vuls/id/567764

 

0x04 ʱ¼äÏß

2021-04-20  OracleÐû²¼Äþ¾²¸üÐÂ

2021-04-21  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png