¡¾Â©¶´Í¨¸æ¡¿Oracle 10Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-10-20

0x00 ©¶´¸ÅÊö

2021Äê10ÔÂ19ÈÕ £¬OracleÐû²¼ÁË10Ô·ݵÄÄþ¾²¸üР£¬±¾´ÎÐû²¼µÄÄþ¾²¸üй²¼Æ419¸ö £¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Financial Services Applications¡¢Oracle Enterprise Manager¡¢Oracle Fusion Middleware¡¢Oracle Java SE¡¢Oracle MySQLºÍOracle SystemsµÈ¶à¸ö²úÎïºÍ×é¼þ¡£

 

0x01 ©¶´ÏêÇé

image.png

l  Oracle Fusion Middleware¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË38¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÄþ¾²¸üР£¬ÆäÖÐÓÐ 30¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣱ¾´ÎÐû²¼µÄ¸üÐÂÉæ¼°¶à¸öOracle WebLogic Server©¶´£ºCVE-2021-35617¡¢CVE-2021-35620ºÍCVE-2021-35552µÈ £¬ÆäÖÐCVE-2021-35617µÄCVSSÆÀ·ÖΪ9.8 £¬¹¥»÷ÅÓ´ó¶ÈµÍ £¬ÇÒÎÞÐèÓû§½»»¥¡£¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPЭÒé¶ÔOracle WebLogic ServerÌᳫ¹¥»÷ £¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆOracle WebLogic Server¡£


l  Oracle Communications Applications¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË19¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÄþ¾²¸üР£¬ÆäÖÐÓÐ14¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÑÏÖØ©¶´°üÂÞCVE-2021-3177 £¬ÆäCVSSÆÀ·ÖΪ9.8¡£

 

l  Oracle E-Business Suite¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË18¸öÊÊÓÃÓÚOracle E-Business Suite µÄÄþ¾²¸üР£¬ÆäÖÐÓÐ4¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖаüÂÞCVE-2021-35566¡¢CVE-2021-2483¡¢CVE-2021-35536ºÍCVE-2021-35585µÈ11¸ö¸ßΣ©¶´ £¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ8.1¡£

 

l  Oracle Enterprise Manager¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË8¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÄþ¾²¸üР£¬ÆäÖÐÓÐ5¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖصÄ©¶´ÎªCVE-2021-26691£¨CVSSÆÀ·ÖΪ9.8£© £¬¸Ã©¶´µÄÀûÓÃÅÓ´ó¶ÈµÍ £¬ÇÒÎÞÐèÓû§½»»¥¡£´ËÍâ £¬Oracle»¹ÐÞ¸´ÁË°üÂÞCVE-2021-2137ºÍCVE-2021-29505ÔÚÄÚµÄÆäËü7¸öÄþ¾²Â©¶´¡£

 

l  Oracle Financial Services Applications¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË44¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÄþ¾²¸üР£¬ÆäÖÐÓÐ26¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÑÏÖØ©¶´°üÂÞCVE-2021-21345¡¢CVE-2020-5413ºÍCVE-2020-10683 £¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£

 

l  Oracle Java SE¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË15¸öÊÊÓÃÓÚOracle Java SEµÄÄþ¾²¸üР£¬ÆäÖÐÓÐ13¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖиßΣ©¶´°üÂÞCVE-2021-3517¡¢CVE-2021-35560ºÍCVE-2021-27290¡£ÆäÖÐ £¬CVE-2021-3517ºÍCVE-2021-35560Ó°ÏìÁËJava SE 8u301¡£

 

l  Oracle MySQL¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË66¸öÊÊÓÃÓÚOracle MySQLµÄÄþ¾²¸üР£¬ÆäÖÐÓÐ10¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÑÏÖØ©¶´°üÂÞCVE-2021-22931£¨Ó°ÏìMySQL¼¯Èº£©ºÍCVE-2021-3711£¨Ó°ÏìMySQL ·þÎñÆ÷£© £¬Õâ2¸ö©¶´µÄCVSSÆÀ·Ö¾ùΪ9.8 £¬¹¥»÷ÅÓ´ó¶ÈµÍ £¬ÇÒÎÞÐèÓû§½»»¥¡£

 

l  Oracle Systems¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË5¸öÊÊÓÃÓÚOracle SystemsµÄÄþ¾²¸üР£¬ÆäÖÐÓÐ2¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÑÏÖØ©¶´°üÂÞCVE-2021-26691 £¬ÆäCVSSÆÀ·Ö¾ùΪ9.8 £¬¹¥»÷ÅÓ´ó¶ÈµÍ £¬ÇÒÎÞÐèÓû§½»»¥¡£´ËÍâ £¬Oracle»¹Ðû²¼ÁËCVE-2021-35539¡¢CVE-2021-35589¡¢CVE-2021-35549ºÍCVE-2020-1968µÈ¶à¸ö©¶´µÄ²¹¶¡¡£

 

0x02 ´¦Öý¨Òé

Ä¿Ç°OracleÒѾ­Ðû²¼ÁËÏà¹Ø²¹¶¡ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§¼°Ê±Éý¼¶¸üС£

©¶´ÁÐ±í¼°Ó°Ï췶ΧÇë²Î¿¼Oracle¹Ù·½Í¨¸æ£º

https://www.oracle.com/security-alerts/cpuoct2021.html

 

»º½â´ëÊ©

Õë¶ÔWebLogic £¬½¨Òé½ûÓÃT3ЭÒé»òIIOPЭÒé¡£

½ûÓÃT3ЭÒé £¬¾ßÌå²Ù×÷£º

1£©½øÈëWebLogic¿ØÖÆ̨ £¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖÐ £¬½øÈë¡°Äþ¾²¡±Ñ¡ÏҳÃæ £¬µã»÷¡°É¸Ñ¡Æ÷¡± £¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£

2)ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl £¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s £¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£

3£©Éú´æºóÐèÖØÐÂÆô¶¯ £¬¹æÔò·½¿ÉÉúЧ¡£

image.png

 

½ûÓÃIIOPЭÒé £¬¾ßÌå²Ù×÷£º

µÇ½WebLogic¿ØÖÆ̨ £¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer

image.png

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuoct2021.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22931

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-10-20

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png