¡¾Îó²îͨ¸æ¡¿Oracle Identity Manager Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2026-21992)
Ðû²¼Ê±¼ä 2026-04-08Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Oracle Identity Manager Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2026-21992 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2026-4-8 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Oracle Identity Manager ÊÇOracle Fusion MiddlewareϵͳÖеÄÉí·ÝÓë»á¼ûÖÎÀí×é¼þ£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÆóÒµÓû§Éí·ÝÉúÃüÖÜÆÚÖÎÀí¡¢È¨ÏÞ·ÖÅÉÓëºÏ¹æ¿ØÖÆ¡£¡£¡£¡£¡£¡£Oracle Web Services ManagerÔòÓÃÓÚWebЧÀÍÇå¾²ÖÎÀíÓëÕ½ÂÔ¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ö§³ÖЧÀÍÈÏÖ¤¡¢ÊÚȨ¡¢Éó¼ÆÓë¼ÓÃܵȹ¦Ð§£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶SOAºÍ΢ЧÀͼܹ¹ÇéÐÎÖС£¡£¡£¡£¡£¡£
2026Äê4ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Oracle Identity ManagerÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚOracle Identity ManagerºÍOracle Web Services ManagerÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚϵͳÔÚÔ¶³Ì½Ó¿Ú´¦Öóͷ£Àú³ÌÖÐȱ·¦ÓÐÓõÄÉí·ÝÈÏÖ¤ÓëÊäÈëУÑé»úÖÆ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂδÊÚȨ¹¥»÷Õß¿ÉÖ±½Óͨ¹ýÍøÂç½á¹¹¶ñÒâÇëÇó´¥·¢Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐèµÇ¼¼´¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨ÏÞ£¬£¬£¬£¬£¬£¬£¬½øÒ»²½ÊµÑéºáÏòÉøÍ¸¡¢Êý¾ÝÇÔÈ¡»òЧÀÍÆÆËðµÈ¹¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£¸ÃÎó²î¾ßÓÐʹÓÃÃż÷µÍ¡¢Ó°Ïì¹æÄ£¹ãµÄÌØµã£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÆóÒµÒªº¦ÓªÒµÏµÍ³Ê§¿Ø£¬£¬£¬£¬£¬£¬£¬²¢±£´æÎ¥·´Êý¾ÝÇå¾²¼°ºÏ¹æÒªÇó£¨ÈçÊý¾Ý±£»£»£»£»£»£»¤Óë»á¼û¿ØÖÆÒªÇ󣩵ÄΣº¦¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://www.oracle.com/security-alerts/alert-cve-2026-21992.html/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ