Oracle | 10Ô¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-10-210x00 Îó²î¸ÅÊö
2020Äê10ÔÂ20ÈÕ£¬£¬£¬OracleÐû²¼10Ô·ݵÄÇå¾²¸üУ¬£¬£¬ÐÞ¸´Á˶à¸ö²úÆ·ÖеÄÇå¾²Îó²î¡£¡£¡£´Ë´ÎÐû²¼µÄÎó²î²¹¶¡¹²¼Æ402¸ö£¬£¬£¬Ö÷񻃾¼°Oracle Database Server¡¢Oracle Communications¡¢Oracle Fusion Middleware¡¢Oracle Weblogic¡¢Oracle E-Business SuiteºÍOracle MySQLµÈ²úÆ·£¬£¬£¬ÆäÖжà¸öÎó²îÆÀ¼¶ÎªÑÏÖØ¡£¡£¡£
0x01 Îó²îÏêÇé
Oracle Database Server
´Ë´Î¸üÐÂÖаüÀ¨OracleÊý¾Ý¿âµÄ18¸öµÄÇå¾²²¹¶¡¡£¡£¡£ÆäÖÐÓÐ4¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º
Îó²î±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°Ïì¹æÄ£ |
CVE-2020-13935 | Workload Manager (Apache Tomcat) | None | 7.5 | 12.2.0.1, 18c, 19c |
CVE-2020-14734 | Oracle Text | None | 8.1 | 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c |
CVE-2020-14735 | Scheduler | Local Logon | 8.8 | 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c |
Oracle Communications¼° Oracle Communications Applications
´Ë´Î¸üÐÂÖаüÀ¨Oracle CommunicationsµÄ52¸öµÄÇå¾²²¹¶¡ºÍ9¸öOracle Communications ApplicationsÇå¾²²¹¶¡£¬£¬£¬ÆäÖÐÓÐ41¸öOracle CommunicationsÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º
Îó²î±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°Ïì¹æÄ£ |
CVE-2020-2555 | Oracle WebCenter Portal | Database Module (Oracle Coherence) | 9.8 | 12.2.1.3.0£¬£¬£¬ 12.2.1.4.0 |
CVE-2020-10683 | Oracle Communications Unified Inventory Management | Core (dom4j) | 9.8 | 7.3.0£¬£¬£¬7.4.0 |
CVE-2020-10878 | Oracle Communications Billing and Revenue Management | Core (Perl) | 8.6 | 12.0.0.2.0£¬£¬£¬ 12.0.0.3.0 |
CVE-2020-11973 | Oracle Communications Diameter Signaling Router (DSR) | IDIH (Apache Camel) | 9.8 | IDIH: 8.0.0-8.2.2 |
CVE-2020-11984 | Oracle Communications Element Manager | Core (Apache HTTP Server) | 9.8 | 8.2.0-8.2.2 |
Oracle Fusion Middleware
´Ë´Î¸üÐÂÖаüÀ¨Oracle Fusion MiddlewareµÄ46¸öÇå¾²²¹¶¡¡£¡£¡£ÆäÖÐÓÐ36¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£ÆäÖÐÉæ¼°Á˶à¸öWeblogic·´ÐòÁл¯Îó²î£¬£¬£¬ÕâЩÎó²îÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýHTTP¡¢IIOP¡¢T3ÐÒé·¢ËͶñÒâÇëÇ󣬣¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë¡£¡£¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º
Îó²î±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°Ïì¹æÄ£ |
CVE-2020-14820 | Oracle WebLogic Server | Core | 7.5 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14825 | Oracle WebLogic Server | Core | 9.8 | 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14841 | Oracle WebLogic Server | Core | 9.8 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14859 | Oracle WebLogic Server | Core | 9.8 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14882 | Oracle WebLogic Server | Console | 9.8 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
Oracle E-Business Suite
´Ë´Î¸üаüÀ¨Oracle E-Business SuiteµÄ27¸öÇå¾²²¹¶¡¡£¡£¡£ÆäÖеÄ25¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º
Îó²î±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°Ïì¹æÄ£ |
CVE-2020-14805 | Oracle E-Business Suite Secure Enterprise Search | Search Integration Engine | 9.1 | 12.1.3, 12.2.3 - 12.2.10 |
CVE-2020-14855 | Oracle Universal Work Queue | Work Provider Administration | 9.8 | 12.1.3 |
CVE-2020-14862 | Oracle Universal Work Queue | Internal Operations | 8.8 | 12.2.3 - 12.2.9 |
CVE-2020-14875 | Oracle Marketing | Marketing Administration | 9.1 | 12.1.1 - 12.1.3, 12.2.3 - 12.2.10 |
CVE-2020-14876 | Oracle Trade Management | User Interface | 9.1 | 12.1.1 - 12.1.3, 12.2.3 - 12.2.10 |
Oracle MySQL
´Ë´Î¸üÐÂÖаüÀ¨Oracle MysqlµÄ54¸öµÄÇå¾²²¹¶¡¡£¡£¡£ÆäÖÐÓÐ4¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£²¿·ÖÑÏÖØÎó²îÈçÏ£º
Îó²î±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°Ïì¹æÄ£ |
CVE-2020-8174 | MySQL Cluster | Cluster: JS module (Node.js) | 9.8 | 7.3.30 and prior, 7.4.29 and prior, 7.5.19 and prior, 7.6.15 and prior, 8.0.21 and prior |
CVE-2020-13935 | MySQL Enterprise Monitor | Monitoring: General (Apache Tomcat) | 7.5 | 8.0.21 and prior |
CVE-2020-14878 | MySQL Server | Server: Security: LDAP Auth | 8.0 | 8.0.21 and prior |
±ðµÄ£¬£¬£¬ÔÚ±¾´ÎÐû²¼µÄ¶à¸öÇå¾²Îó²îÖл¹°üÀ¨2¸öÆÀ·ÖΪ10£¨Âú·Ö10·Ö£©µÄÎó²î£¬£¬£¬ÈçÏ£º
Îó²î±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°Ïì¹æÄ£ |
CVE-2020-1953 | Oracle Healthcare Foundation | Self Service Analytics (Apache Commons Configuration) | 10.0 | 7.1.1£¬£¬£¬7.2.0£¬£¬£¬7.2.1£¬£¬£¬7.3.0 |
CVE-2020-14871 | Oracle Solaris | Pluggable authentication module | 10.0 | 10£¬£¬£¬11 |
Oracle Healthcare Foundation Self Service AnalyticsÎó²î£¨CVE-2020-1953£©
¸ÃÎó²îÊÇÓÉÓÚOracle Healthcare FoundationµÄ×ÔÖúÆÊÎöЧÀÍ£¨Apache Commons Configuration£©Ê¹ÓõÚÈý·½¿âÀ´ÆÊÎöYAMLÎļþ£¬£¬£¬ÈôÊÇYAML°üÀ¨ÌØÊâÓï¾ä£¬£¬£¬ÔòĬÈÏÇéÐÎÏÂËüÔÊÐíʵÀý»¯Àà¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕµ¼Óû§´Ó²»ÊÜÐÅÈεÄÔ´¼ÓÔØYAMLÎļþÀ´Ê¹ÓôËÎó²î¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚÖ÷»úÓ¦ÓóÌÐòµÄ¿ØÖƹæÄ£Ö®Íâ¼ÓÔØ²¢Ö´ÐдúÂë¡£¡£¡£
Ó°Ïì¹æÄ££º
Apache Commons Configuration2.2£¬£¬£¬2.3£¬£¬£¬2.4£¬£¬£¬2.5£¬£¬£¬2.6
Oracle Healthcare Foundation 7.1.1£¬£¬£¬7.2.0£¬£¬£¬7.2.1£¬£¬£¬7.3.0
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1953
Oracle Solaris Pluggable authentication moduleÎó²î(CVE-2020-14871)
¸ÃÎó²îµÄϸ½ÚÔÝʱδ¹ûÕæ¡£¡£¡£
Ó°Ïì¹æÄ££º
Oracle Solaris10£¬£¬£¬11
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14871
0x02 ´¦Öóͷ£½¨Òé
½¨Òé²Î¿¼¹Ù·½Ðû²¼µÄ²¹¶¡¸üÐÂÐÅϢʵʱÐÞ¸´»òÉý¼¶ÖÁÇå¾²°æ±¾¡£¡£¡£
Á´½ÓµØµã£º
https://www.oracle.com/security-alerts/cpuoct2020.html
ÏÂÔØµØµã£º
https://www.oracle.com/cn/downloads/
ÆäËü²½·¥£º
ÈôÊDz»ÒÀÀµT3ÐæÅºÍIIOPÐÒé¾ÙÐÐJVMͨѶ£¬£¬£¬Ôò½¨Òé½ûÓᣡ£¡£
0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/
https://us-cert.cisa.gov/ncas/current-activity/2020/10/20/oracle-releases-october-2020-security-bulletin-0
0x04 ʱ¼äÏß
2020-10-20 OracleÐû²¼Çå¾²¸üÐÂ
2020-10-21 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/