Oracle | 10Ô¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-10-21

0x00 Îó²î¸ÅÊö

2020Äê10ÔÂ20ÈÕ£¬ £¬£¬OracleÐû²¼10Ô·ݵÄÇå¾²¸üУ¬ £¬£¬ÐÞ¸´Á˶à¸ö²úÆ·ÖеÄÇå¾²Îó²î¡£¡£ ¡£´Ë´ÎÐû²¼µÄÎó²î²¹¶¡¹²¼Æ402¸ö£¬ £¬£¬Ö÷񻃾¼°Oracle Database Server¡¢Oracle Communications¡¢Oracle Fusion Middleware¡¢Oracle Weblogic¡¢Oracle E-Business SuiteºÍOracle MySQLµÈ²úÆ·£¬ £¬£¬ÆäÖжà¸öÎó²îÆÀ¼¶ÎªÑÏÖØ¡£¡£ ¡£

 

0x01 Îó²îÏêÇé

 

image.png

 

Oracle Database Server

´Ë´Î¸üÐÂÖаüÀ¨OracleÊý¾Ý¿âµÄ18¸öµÄÇå¾²²¹¶¡¡£¡£ ¡£ÆäÖÐÓÐ4¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£ ¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º

Îó²î±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°Ïì¹æÄ£

CVE-2020-13935

Workload Manager (Apache Tomcat)

None

7.5

12.2.0.1, 18c, 19c

CVE-2020-14734

Oracle Text

None

8.1

11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c

CVE-2020-14735

Scheduler

Local Logon

8.8

11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c

 

 

Oracle Communications¼° Oracle Communications Applications

´Ë´Î¸üÐÂÖаüÀ¨Oracle CommunicationsµÄ52¸öµÄÇå¾²²¹¶¡ºÍ9¸öOracle Communications ApplicationsÇå¾²²¹¶¡£¬ £¬£¬ÆäÖÐÓÐ41¸öOracle CommunicationsÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£ ¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º

Îó²î±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°Ïì¹æÄ£

CVE-2020-2555

Oracle WebCenter Portal

Database Module (Oracle Coherence)

9.8

12.2.1.3.0£¬ £¬£¬

12.2.1.4.0

CVE-2020-10683

Oracle Communications Unified Inventory Management

Core (dom4j)

9.8

7.3.0£¬ £¬£¬7.4.0

CVE-2020-10878

Oracle Communications Billing and Revenue Management

Core (Perl)

8.6

12.0.0.2.0£¬ £¬£¬ 12.0.0.3.0

CVE-2020-11973

Oracle Communications Diameter Signaling Router (DSR)

IDIH (Apache Camel)

9.8

IDIH: 8.0.0-8.2.2

CVE-2020-11984

Oracle Communications Element Manager

Core (Apache HTTP Server)

9.8

8.2.0-8.2.2

 

 

Oracle Fusion Middleware

´Ë´Î¸üÐÂÖаüÀ¨Oracle Fusion MiddlewareµÄ46¸öÇå¾²²¹¶¡¡£¡£ ¡£ÆäÖÐÓÐ36¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£ ¡£ÆäÖÐÉæ¼°Á˶à¸öWeblogic·´ÐòÁл¯Îó²î£¬ £¬£¬ÕâЩÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýHTTP¡¢IIOP¡¢T3ЭÒé·¢ËͶñÒâÇëÇó£¬ £¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë¡£¡£ ¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º

Îó²î±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°Ïì¹æÄ£

CVE-2020-14820

Oracle WebLogic Server

Core

7.5

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14825

Oracle WebLogic Server

Core

9.8

12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14841

Oracle WebLogic Server

Core

9.8

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14859

Oracle WebLogic Server

Core

9.8

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14882

Oracle WebLogic Server

Console

9.8

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

 

 

Oracle E-Business Suite

´Ë´Î¸üаüÀ¨Oracle E-Business SuiteµÄ27¸öÇå¾²²¹¶¡¡£¡£ ¡£ÆäÖеÄ25¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£ ¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º

Îó²î±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°Ïì¹æÄ£

CVE-2020-14805

Oracle E-Business Suite Secure Enterprise Search

Search Integration Engine

9.1

12.1.3, 12.2.3 - 12.2.10

CVE-2020-14855

Oracle Universal Work Queue

Work Provider Administration

9.8

12.1.3

CVE-2020-14862

Oracle Universal Work Queue

Internal Operations

8.8

12.2.3 - 12.2.9

CVE-2020-14875

Oracle Marketing

Marketing Administration

9.1

12.1.1 - 12.1.3, 12.2.3 - 12.2.10

CVE-2020-14876

Oracle Trade Management

User Interface

9.1

12.1.1 - 12.1.3, 12.2.3 - 12.2.10

 

 

Oracle MySQL

´Ë´Î¸üÐÂÖаüÀ¨Oracle MysqlµÄ54¸öµÄÇå¾²²¹¶¡¡£¡£ ¡£ÆäÖÐÓÐ4¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£ ¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º

Îó²î±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°Ïì¹æÄ£

CVE-2020-8174

MySQL Cluster

Cluster: JS module (Node.js)

9.8

7.3.30 and prior,

7.4.29 and prior,

7.5.19 and prior,

7.6.15 and prior,

8.0.21 and prior

CVE-2020-13935

MySQL Enterprise Monitor

Monitoring: General (Apache Tomcat)

7.5

8.0.21 and prior

CVE-2020-14878

MySQL Server

Server: Security: LDAP Auth

8.0

8.0.21 and prior

 

±ðµÄ£¬ £¬£¬ÔÚ±¾´ÎÐû²¼µÄ¶à¸öÇå¾²Îó²îÖл¹°üÀ¨2¸öÆÀ·ÖΪ10£¨Âú·Ö10·Ö£©µÄÎó²î£¬ £¬£¬ÈçÏ£º

Îó²î±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°Ïì¹æÄ£

CVE-2020-1953

Oracle Healthcare Foundation

Self Service Analytics (Apache Commons Configuration)

10.0

7.1.1£¬ £¬£¬7.2.0£¬ £¬£¬7.2.1£¬ £¬£¬7.3.0

CVE-2020-14871

Oracle Solaris

Pluggable authentication module

10.0

10£¬ £¬£¬11

 

Oracle Healthcare Foundation Self Service AnalyticsÎó²î£¨CVE-2020-1953£©

¸ÃÎó²îÊÇÓÉÓÚOracle Healthcare FoundationµÄ×ÔÖúÆÊÎöЧÀÍ£¨Apache Commons Configuration£©Ê¹ÓõÚÈý·½¿âÀ´ÆÊÎöYAMLÎļþ£¬ £¬£¬ÈôÊÇYAML°üÀ¨ÌØÊâÓï¾ä£¬ £¬£¬ÔòĬÈÏÇéÐÎÏÂËüÔÊÐíʵÀý»¯Àà¡£¡£ ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕµ¼Óû§´Ó²»ÊÜÐÅÈεÄÔ´¼ÓÔØYAMLÎļþÀ´Ê¹ÓôËÎó²î¡£¡£ ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚÖ÷»úÓ¦ÓóÌÐòµÄ¿ØÖƹæÄ£Ö®Íâ¼ÓÔØ²¢Ö´ÐдúÂë¡£¡£ ¡£

Ó°Ïì¹æÄ££º

Apache Commons Configuration2.2£¬ £¬£¬2.3£¬ £¬£¬2.4£¬ £¬£¬2.5£¬ £¬£¬2.6

Oracle Healthcare Foundation 7.1.1£¬ £¬£¬7.2.0£¬ £¬£¬7.2.1£¬ £¬£¬7.3.0

²Î¿¼Á´½Ó£º

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1953

 

Oracle Solaris Pluggable authentication moduleÎó²î(CVE-2020-14871)

¸ÃÎó²îµÄϸ½ÚÔÝʱδ¹ûÕæ¡£¡£ ¡£

Ó°Ïì¹æÄ££º

Oracle Solaris10£¬ £¬£¬11

²Î¿¼Á´½Ó£º

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14871

 

0x02 ´¦Öóͷ£½¨Òé

½¨Òé²Î¿¼¹Ù·½Ðû²¼µÄ²¹¶¡¸üÐÂÐÅϢʵʱÐÞ¸´»òÉý¼¶ÖÁÇå¾²°æ±¾¡£¡£ ¡£

Á´½ÓµØµã£º

https://www.oracle.com/security-alerts/cpuoct2020.html

ÏÂÔØµØµã£º

https://www.oracle.com/cn/downloads/

ÆäËü²½·¥£º

ÈôÊDz»ÒÀÀµT3ЭæÅºÍIIOPЭÒé¾ÙÐÐJVMͨѶ£¬ £¬£¬Ôò½¨Òé½ûÓᣡ£ ¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuoct2020.html

https://www.oracle.com/security-alerts/

https://us-cert.cisa.gov/ncas/current-activity/2020/10/20/oracle-releases-october-2020-security-bulletin-0

 

0x04 Ê±¼äÏß

2020-10-20  OracleÐû²¼Çå¾²¸üÐÂ

2020-10-21  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png