¡¾Â©¶´Í¨¸æ¡¿Oracle 10Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2021-10-200x00 ©¶´¸ÅÊö
2021Äê10ÔÂ19ÈÕ£¬OracleÐû²¼ÁË10Ô·ݵÄÄþ¾²¸üУ¬±¾´ÎÐû²¼µÄÄþ¾²¸üй²¼Æ419¸ö£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Financial Services Applications¡¢Oracle Enterprise Manager¡¢Oracle Fusion Middleware¡¢Oracle Java SE¡¢Oracle MySQLºÍOracle SystemsµÈ¶à¸ö²úÎïºÍ×é¼þ¡£
0x01 ©¶´ÏêÇé
l Oracle Fusion Middleware¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË38¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ 30¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣱ¾´ÎÐû²¼µÄ¸üÐÂÉæ¼°¶à¸öOracle WebLogic Server©¶´£ºCVE-2021-35617¡¢CVE-2021-35620ºÍCVE-2021-35552µÈ£¬ÆäÖÐCVE-2021-35617µÄCVSSÆÀ·ÖΪ9.8£¬¹¥»÷ÅÓ´ó¶ÈµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPÐÒé¶ÔOracle WebLogic ServerÌᳫ¹¥»÷£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆOracle WebLogic Server¡£
l Oracle Communications Applications¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË19¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÄþ¾²¸üУ¬ÆäÖÐÓÐ14¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÑÏÖØ©¶´°üÂÞCVE-2021-3177£¬ÆäCVSSÆÀ·ÖΪ9.8¡£
l Oracle E-Business Suite¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË18¸öÊÊÓÃÓÚOracle E-Business Suite µÄÄþ¾²¸üУ¬ÆäÖÐÓÐ4¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖаüÂÞCVE-2021-35566¡¢CVE-2021-2483¡¢CVE-2021-35536ºÍCVE-2021-35585µÈ11¸ö¸ßΣ©¶´£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ8.1¡£
l Oracle Enterprise Manager¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË8¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ5¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖصÄ©¶´ÎªCVE-2021-26691£¨CVSSÆÀ·ÖΪ9.8£©£¬¸Ã©¶´µÄÀûÓÃÅÓ´ó¶ÈµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£´ËÍ⣬Oracle»¹ÐÞ¸´ÁË°üÂÞCVE-2021-2137ºÍCVE-2021-29505ÔÚÄÚµÄÆäËü7¸öÄþ¾²Â©¶´¡£
l Oracle Financial Services Applications¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË44¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ26¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÑÏÖØ©¶´°üÂÞCVE-2021-21345¡¢CVE-2020-5413ºÍCVE-2020-10683£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£
l Oracle Java SE¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË15¸öÊÊÓÃÓÚOracle Java SEµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ13¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖиßΣ©¶´°üÂÞCVE-2021-3517¡¢CVE-2021-35560ºÍCVE-2021-27290¡£ÆäÖУ¬CVE-2021-3517ºÍCVE-2021-35560Ó°ÏìÁËJava SE 8u301¡£
l Oracle MySQL¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË66¸öÊÊÓÃÓÚOracle MySQLµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ10¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÑÏÖØ©¶´°üÂÞCVE-2021-22931£¨Ó°ÏìMySQL¼¯Èº£©ºÍCVE-2021-3711£¨Ó°ÏìMySQL ·þÎñÆ÷£©£¬Õâ2¸ö©¶´µÄCVSSÆÀ·Ö¾ùΪ9.8£¬¹¥»÷ÅÓ´ó¶ÈµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£
l Oracle Systems¶à¸öÄþ¾²Â©¶´
Oracle´Ë´Î¹²Ðû²¼ÁË5¸öÊÊÓÃÓÚOracle SystemsµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ2¸ö©¶´ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÑÏÖØ©¶´°üÂÞCVE-2021-26691£¬ÆäCVSSÆÀ·Ö¾ùΪ9.8£¬¹¥»÷ÅÓ´ó¶ÈµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£´ËÍ⣬Oracle»¹Ðû²¼ÁËCVE-2021-35539¡¢CVE-2021-35589¡¢CVE-2021-35549ºÍCVE-2020-1968µÈ¶à¸ö©¶´µÄ²¹¶¡¡£
0x02 ´¦Öý¨Òé
Ä¿Ç°OracleÒѾÐû²¼ÁËÏà¹Ø²¹¶¡£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¼°Ê±Éý¼¶¸üС£
©¶´ÁÐ±í¼°Ó°Ï췶ΧÇë²Î¿¼Oracle¹Ù·½Í¨¸æ£º
https://www.oracle.com/security-alerts/cpuoct2021.html
»º½â´ëÊ©
Õë¶ÔWebLogic£¬½¨Òé½ûÓÃT3ÐÒé»òIIOPÐÒé¡£
½ûÓÃT3ÐÒ飬¾ßÌå²Ù×÷£º
1£©½øÈëWebLogic¿ØÖÆ̨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡ÏҳÃ棬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£
2)ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£
3£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£
½ûÓÃIIOPÐÒ飬¾ßÌå²Ù×÷£º
µÇ½WebLogic¿ØÖÆ̨£¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer
0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpuoct2021.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22931
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-10-20 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¶«Éƽ̨
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º