¡¾Îó²îͨ¸æ¡¿Oracle 7Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-07-210x00 Îó²î¸ÅÊö
2021Äê7ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬OracleÐû²¼ÁË7Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼Æ342¸ö£¬£¬£¬£¬£¬£¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Enterprise ManagerºÍOracle Fusion MiddlewareµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé

Oracle Fusion Middleware¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË48¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ 35¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£ÆäÖаüÀ¨¶à¸öWebLogic ServerÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOP»òT3ÐÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë»ò¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-2394¡¢CVE-2021-2397ºÍCVE-2021-2382£¬£¬£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£¡£
Oracle Communications Applications¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË33 ¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ 22 ¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2020-11612¡¢CVE-2021-3177¡¢CVE-2020-17530ºÍCVE-2019-17195£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPÐÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£¡£¡£¡£¡£
Oracle E-Business Suite¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË17 ¸öÊÊÓÃÓÚOracle E-Business Suite µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ3¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2021-2355£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2021-2436¡¢CVE-2021-2359ºÍCVE-2021-2361ÔÚÄÚµÄ15¸ö¸ßΣÎó²î¡£¡£¡£¡£¡£
Oracle Enterprise Manager¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË8 ¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¶¼¿ÉÒÔÔÚδ¾ÓÉÉí·ÝÑéÖ¤µÄÇéÐÎÏÂÔ¶³ÌʹÓᣡ£¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2020-10683£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2019-5064ÔÚÄ򵀮äËü7¸öÇå¾²Îó²î¡£¡£¡£¡£¡£
Oracle Financial Services Applications¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË22¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ 17¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2019-0228¡¢CVE-2021-26117¡¢CVE-2020-5413¡¢CVE-2020-11998ºÍCVE-2020-27218£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPÐÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚOracleÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpujul2021.html
»º½â²½·¥
½ûÓÃT3ÐÒ飺
1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£¡£¡£
2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£¡£¡£
3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£¡£¡£

½ûÓÃIIOPÐÒé:
Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬£¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpujul2021.html
https://us-cert.cisa.gov/ncas/current-activity/2021/07/20/oracle-releases-july-2021-critical-patch-update
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2394
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-21 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ