Oracle 4Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-04-21

0x00 Îó²î¸ÅÊö

2021Äê04ÔÂ20ÈÕ£¬£¬ £¬£¬OracleÐû²¼ÁË4Ô·ݵÄÇå¾²¸üУ¬£¬ £¬£¬±¾´ÎÐû²¼µÄÇå¾²²¹¶¡¹²¼Æ390¸ö£¬£¬ £¬£¬Éæ¼°Oracle Fusion Middleware¡¢Oracle E-Business Suite¡¢Oracle Communications ApplicationsºÍOracle MySQLµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£ ¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

ÔÚ±¾´ÎÐû²¼µÄÇå¾²²¹¶¡ÖУ¬£¬ £¬£¬Oracle Fusion MiddlewareÏà¹ØµÄ²¹¶¡Îª45¸ö£¬£¬ £¬£¬ÆäÖÐ36¸öÎó²îÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£Weblogic Server²¿·ÖÎó²îÏêÇéÈçÏ£º

Oracle WebLogic Server Coherence ContainerÇå¾²Îó²î£¨CVE-2021-2135£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýT3»òIIOPЭÒé·¢ËͶñÒâÇëÇ󣬣¬ £¬£¬×îÖÕ¿ØÖÆÐ§ÀÍÆ÷¡£ ¡£¡£¡£¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬ £¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£ ¡£¡£¡£

Ó°Ïì¹æÄ£

12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0

 

Oracle WebLogic Server CoreÇå¾²Îó²î£¨CVE-2021-2136£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPЭÒé·¢ËͶñÒâÇëÇ󣬣¬ £¬£¬×îÖÕ¿ØÖÆÐ§ÀÍÆ÷¡£ ¡£¡£¡£¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬ £¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£ ¡£¡£¡£

Ó°Ïì¹æÄ£

12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0

 

Oracle WebLogic Server TopLink IntegrationÇå¾²Îó²î£¨CVE-2021-2157£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýHTTP·¢ËͶñÒâÇëÇ󣬣¬ £¬£¬×îÖÕ¿ÉÒÔδÊÚȨ»á¼ûÒªº¦Êý¾Ý¡£ ¡£¡£¡£¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬ £¬£¬ÆäCVSSÆÀ·ÖΪ7.5¡£ ¡£¡£¡£

Ó°Ïì¹æÄ£

10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0

 

±ðµÄ£¬£¬ £¬£¬ÔÚOracle±¾´ÎÐû²¼µÄÇå¾²²¹¶¡ÖУº

ÓëOracle Communications ApplicationsÏà¹ØµÄ²¹¶¡Îª13¸ö£¬£¬ £¬£¬ÆäÖÐCVE-2020-11612ºÍCVE-2020-28052ÆÀ·ÖΪ9.8£¬£¬ £¬£¬¹¥»÷ÕßÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉʹÓðüÀ¨Õâ2¸öÎó²îÔÚÄÚµÄ12¸öÇå¾²Îó²î¡£ ¡£¡£¡£

ÓëE-Business SuiteÏà¹ØµÄ²¹¶¡Îª70¸ö£¬£¬ £¬£¬ÆäÖÐCVE-2021-2200ºÍCVE-2021-2205ÆÀ·ÖΪ9.1£¬£¬ £¬£¬¹¥»÷ÕßÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓðüÀ¨Õâ2¸öÎó²îÔÚÄÚµÄ22¸öÇå¾²Îó²î¡£ ¡£¡£¡£

ÓëOracle MySQLÏà¹ØµÄ²¹¶¡Îª49¸ö£¬£¬ £¬£¬ÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉʹÓõÄÎó²îΪ10¸ö£¬£¬ £¬£¬ÆäÖÐCVE-2021-3449ºÍCVE-2021-3450£¨¾ùΪMySQL ServerÖеÄOpenSSLÎÊÌ⣩ÆÀ·Ö»®·ÖΪ7.5ºÍ7.4, CVE-2021-2307ΪMySQL for WindowsÖеÄȨÏÞÌáÉýÎó²î£¬£¬ £¬£¬¸ÃÎó²îÐè¾­ÓÉÑéÖ¤²Å»ªÊ¹Ó㬣¬ £¬£¬ÆäCVSSÆÀ·ÖΪ6.1¡£ ¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚOracleÒѾ­Ðû²¼Ïà¹ØÇå¾²²¹¶¡£¬£¬ £¬£¬½¨Ò龡¿ìÓ¦Óᣠ¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2021.html

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuapr2021.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2135

https://kb.cert.org/vuls/id/567764

 

0x04 ʱ¼äÏß

2021-04-20  OracleÐû²¼Çå¾²¸üÐÂ

2021-04-21  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png