ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ29ÖÜ

Ðû²¼Ê±¼ä 2020-07-20

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê07ÔÂ13ÈÕÖÁ07ÔÂ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î82¸ö£¬ £¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç³öÎó²î£»£»£»Oracle Fusion Middleware WebLogic Server CVE-2020-14625í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»Oracle GoldenGate Process Management×é¼þ´úÂëÖ´ÐÐÎó²î£»£»£»Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´ÐÐÎó²î; ABB IRC5 OPCĬÈÏÓ²±àÂëÎó²î¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇVMwareÐÞ¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨÎó²î£»£»£»ºÚ¿ÍÈëÇÖÇå¾²¹«Ë¾DataViperЧÀÍÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢£»£»£»SAPÐû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´NetWeaverÖеÄÑÏÖØÎó²î£»£»£»ºÚ¿ÍÔÚ°µÍø¹ûÕæwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý£»£»£»Ë¼¿ÆÐû²¼¶àÖÖ²úÆ·µÄÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´´úÂëÖ´ÐÐÎó²î¡£ ¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£



>Ö÷ÒªÇå¾²Îó²îÁбí


1.Microsoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç³öÎó²î


Microsoft Windows Server DNS Server´¦Öóͷ£ÏìÓ¦²ÎÊý±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1350


2. Oracle Fusion Middleware WebLogic Server CVE-2020-14625í§Òâ´úÂëÖ´ÐÐÎó²î


Oracle Fusion Middleware WebLogic Server±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£

https://www.oracle.com/security-alerts/cpujul2020.html


3. Oracle GoldenGate Process Management×é¼þ´úÂëÖ´ÐÐÎó²î


Oracle GoldenGate Process Management×é¼þ±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£

https://www.oracle.com/security-alerts/cpujul2020.html


4. Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´ÐÐÎó²î


Adobe Media Encoder´¦Öóͷ£ÒôƵÎļþ±£´æÔ½½çдÎó²î£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ £¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»òÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£

https://helpx.adobe.com/security/products/media-encoder/apsb20-36.html


5. ABB IRC5 OPCĬÈÏÓ²±àÂëÎó²î


ABB IRC5 OPC server±£´æÄ¬ÈÏÓ²±àÂëÎó²î£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ»á¼ûϵͳ¡£ ¡£¡£¡£

https://github.com/aliasrobotics/RVD/issues/3326



> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢VMwareÐÞ¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/10/vmware-releases-security-updates-multiple-products


2¡¢ºÚ¿ÍÈëÇÖÇå¾²¹«Ë¾DataViperЧÀÍÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-breaches-security-firm-in-act-of-revenge/#ftag=RSSbaffb68


3¡¢SAPÐû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´NetWeaverÖеÄÑÏÖØÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/alerts/aa20-195a


4¡¢ºÚ¿ÍÔÚ°µÍø¹ûÕæwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/


5¡¢Ë¼¿ÆÐû²¼¶àÖÖ²úÆ·µÄÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´´úÂëÖ´ÐÐÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products