ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ29ÖÜ

Ðû²¼Ê±¼ä 2020-07-20

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê07ÔÂ13ÈÕÖÁ07ÔÂ19ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´82¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç³ö©¶´  £»Oracle Fusion Middleware WebLogic Server CVE-2020-14625ÈÎÒâ´úÂëÖ´ÐЩ¶´  £»Oracle GoldenGate Process Management×é¼þ´úÂëÖ´ÐЩ¶´  £»Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´ÐЩ¶´; ABB IRC5 OPCĬÈÏÓ²±àÂ멶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇVMwareÐÞ¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ©¶´  £»ºÚ¿ÍÈëÇÖÄþ¾²¹«Ë¾DataViper·þÎñÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢  £»SAPÐû²¼Äþ¾²¸üУ¬ÐÞ¸´NetWeaverÖеÄÑÏÖØ©¶´  £»ºÚ¿ÍÔÚ°µÍø¹ûÈ»wattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý  £»Ë¼¿ÆÐû²¼¶àÖÖ²úÎïµÄÄþ¾²¸üУ¬ÐÞ¸´´úÂëÖ´ÐЩ¶´ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£



>ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç³ö©¶´


Microsoft Windows Server DNS Server´¦ÖÃÏìÓ¦²ÎÊý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ  £»ò¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1350


2. Oracle Fusion Middleware WebLogic Server CVE-2020-14625ÈÎÒâ´úÂëÖ´ÐЩ¶´


Oracle Fusion Middleware WebLogic Server´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ  £»ò¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.oracle.com/security-alerts/cpujul2020.html


3. Oracle GoldenGate Process Management×é¼þ´úÂëÖ´ÐЩ¶´


Oracle GoldenGate Process Management×é¼þ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ  £»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.oracle.com/security-alerts/cpujul2020.html


4. Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´ÐЩ¶´


Adobe Media Encoder´¦ÖÃÒôƵÎļþ´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ  £»òÖ´ÐÐÈÎÒâ´úÂë ¡£

https://helpx.adobe.com/security/products/media-encoder/apsb20-36.html


5. ABB IRC5 OPCĬÈÏÓ²±àÂ멶´


ABB IRC5 OPC server´æÔÚĬÈÏÓ²±àÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊϵͳ ¡£

https://github.com/aliasrobotics/RVD/issues/3326



> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢VMwareÐÞ¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ©¶´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/10/vmware-releases-security-updates-multiple-products


2¡¢ºÚ¿ÍÈëÇÖÄþ¾²¹«Ë¾DataViper·þÎñÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-breaches-security-firm-in-act-of-revenge/#ftag=RSSbaffb68


3¡¢SAPÐû²¼Äþ¾²¸üУ¬ÐÞ¸´NetWeaverÖеÄÑÏÖØ©¶´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/alerts/aa20-195a


4¡¢ºÚ¿ÍÔÚ°µÍø¹ûÈ»wattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/


5¡¢Ë¼¿ÆÐû²¼¶àÖÖ²úÎïµÄÄþ¾²¸üУ¬ÐÞ¸´´úÂëÖ´ÐЩ¶´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products