¡¾Îó²îͨ¸æ¡¿Oracle 7Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-07-21

0x00 Îó²î¸ÅÊö

2021Äê7ÔÂ20ÈÕ£¬£¬£¬£¬OracleÐû²¼ÁË7Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼Æ342¸ö£¬£¬£¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Enterprise ManagerºÍOracle Fusion MiddlewareµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

Oracle Fusion Middleware¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË48¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÇå¾²¸üУ¬£¬£¬£¬ÆäÖÐÓÐ 35¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£ÆäÖаüÀ¨¶à¸öWebLogic ServerÇå¾²Îó²î£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOP»òT3ЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë»ò¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-2394¡¢CVE-2021-2397ºÍCVE-2021-2382£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£

 

Oracle Communications Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË33 ¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÇå¾²¸üУ¬£¬£¬£¬ÆäÖÐÓÐ 22 ¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2020-11612¡¢CVE-2021-3177¡¢CVE-2020-17530ºÍCVE-2019-17195£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£¡£¡£

 

Oracle E-Business Suite¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË17 ¸öÊÊÓÃÓÚOracle E-Business Suite µÄÇå¾²¸üУ¬£¬£¬£¬ÆäÖÐÓÐ3¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2021-2355£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£±ðµÄ£¬£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2021-2436¡¢CVE-2021-2359ºÍCVE-2021-2361ÔÚÄÚµÄ15¸ö¸ßΣÎó²î¡£¡£¡£

 

Oracle Enterprise Manager¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË8 ¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÇå¾²¸üУ¬£¬£¬£¬ÕâЩÎó²î¶¼¿ÉÒÔÔÚδ¾­ÓÉÉí·ÝÑéÖ¤µÄÇéÐÎÏÂÔ¶³ÌʹÓᣡ£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2020-10683£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£±ðµÄ£¬£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2019-5064ÔÚÄ򵀮äËü7¸öÇå¾²Îó²î¡£¡£¡£

 

Oracle Financial Services Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË22¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÇå¾²¸üУ¬£¬£¬£¬ÆäÖÐÓÐ 17¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2019-0228¡¢CVE-2021-26117¡¢CVE-2020-5413¡¢CVE-2020-11998ºÍCVE-2020-27218£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚOracleÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÐÞ¸´¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpujul2021.html

 

»º½â²½·¥

½ûÓÃT3ЭÒ飺

1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£

2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£

3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£

image.png

 

½ûÓÃIIOPЭÒé:

Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

image.png

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpujul2021.html

https://us-cert.cisa.gov/ncas/current-activity/2021/07/20/oracle-releases-july-2021-critical-patch-update

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2394

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-21

Ê×´ÎÐû²¼

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png       image.png