Oracleȫϵ²úÆ·2019Äê10Ô¹ؼü²¹¶¡¸üа²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-17

·ì϶¸ÅÊö


10ÔÂ15ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Oracle°ä²¼ÁË2019Äê10ÔµĹؼü²¹¶¡¸üУ¨CPU£© £¬£¬£¬£¬£¬£¬£¬£¬×÷Ϊ¼¾¶È·ì϶½¨¸´°ä²¼µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£´Ë¸üÐÂÔ̺¬¶à¸öOracle²úÆ·ÖÐ219¸ö²¹¶¡ÖÐ180¸öCVEµÄ½¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£Éæ¼°Oracle Enterprise manager Products Suite¡¢Oracle Fusion Middleware¡¢Oracle Knowledge¡¢Oracle MySQLµÈ¶à¸ö²úÆ·¡£¡£¡£¡£¡£¡£¡£¡£


ÆäÖÐWeblogic Serve´æÔÚ¶à¸ö¸ßΣ·ì϶


Oracle WebLogic Server| CVE-2019-2887, CVE-2019-2890, CVE-2019-2891


CVE-2019-2887ÓëCVE-2019-2890µ¼Ö¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬½ûÓÃT3ºÍ̸²Ù×÷·½Ê½½øÐзÀ»¤¿É²Î¿¼Á´½Óhttps://mp.weixin.qq.com/s/YWTSyEVunQUordwxThrGwA¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-2891¿Éµ¼Ö¹¥»÷ÕßÄÜ·¢ËÍHTTPÒªÇó¹¥»÷WebLogic Server¡£¡£¡£¡£¡£¡£¡£¡£


´Ë±í»¹ÓÐÒÔÏÂWebLogic Server·ì϶±ØÒª½øÐйØ×¢£ºCVE-2019-2888 £¬£¬£¬£¬£¬£¬£¬£¬CVE-2019-2889 £¬£¬£¬£¬£¬£¬£¬£¬CVE-2015-9251 £¬£¬£¬£¬£¬£¬£¬£¬CVE-2019-11358 £¬£¬£¬£¬£¬£¬£¬£¬CVE-2019-17091¡£¡£¡£¡£¡£¡£¡£¡£


±¾¼¾¶ÈµÄCPU»¹Ô̺¬18¸öCVSS 9+·ì϶£»£»£»£»£»£»£»£»ÀûÓÃÕâЩ·ì϶¿ÉÄܵ¼ÖÂδ¾­ÑéÖ¤µÄ½Ó¼û»òÆëÈ«ÊÕÊÜÒ×Êܹ¥»÷µÄ×ʲú¡£¡£¡£¡£¡£¡£¡£¡£


CVE#

Product

BaseScore

CVE-2018-14721

Oracle NoSQL Database

10

CVE-2017-6056

Instantis EnterpriseTrack

9.8

CVE-2019-14379

Primavera Gateway

9.8

CVE-2019-14379

Primavera Unifier

9.8

CVE-2019-3020

Primavera P6 Enterprise Project Portfolio Management

9.3

CVE-2016-4000

Enterprise Manager Base Platform

9.8

CVE-2019-14379

Oracle Banking Platform

9.8

CVE-2019-14379

Oracle Financial Services Analytical Applications Infrastructure

9.8

CVE-2019-2904

Oracle JDeveloper and ADF

9.8

CVE-2016-1000031

Oracle Virtual Directory

9.8

CVE-2017-5645

JD Edwards EnterpriseOne Tools

9.8

CVE-2019-8457

MySQL Workbench

9.8

CVE-2016-0729

PeopleSoft Enterprise PeopleTools

9.8

CVE-2019-3862

PeopleSoft Enterprise PeopleTools

9.1

CVE-2018-19362

MICROS Retail XBRi Loss Prevention

9.8

CVE-2019-14379

Oracle Retail Xstore Point of Service

9.8

CVE-2018-1000007

Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers

9.8

CVE-2016-6814

Agile Recipe Management for Pharmaceuticals

9.8



ÕâÀïÎÒÃǸü¾ßÌ嵨ÃèÊöÁËһЩCVSS 9+ÆÀ·ÖCVE£º


Oracle NoSQLÊý¾Ý¿â| CVE-2018-14721


±¾ÔÂ×îÖµÍ×ÌùÐĵIJ¹¶¡Ö®Ò»½â¾öÁËCVE-2018-14721 £¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇOracle NoSQLÊý¾Ý¿âÖÐÓ°Ïì19.3.12֮ǰËùÓа汾µÄ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚJackson DATABONE NOSQL×é¼þÄÚ¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýHTTP½øÐÐÍøÂç½Ó¼ûµÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÊÕÊÜOracle NoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶ÒÔǰÔÚÆäËûOracle²úÆ·£¨Ô̺¬Oracle 2019Äê1ÔµÄCPU£©ÖÐÒѵõ½½â¾ö¡£¡£¡£¡£¡£¡£¡£¡£


Oracle MySQL| CVE-2019-8457


CVE-2019-8457ÊÇOracle MySQLµÄsqlite×é¼þÖеĶÑÔ½½ç¶ÁÈ¡·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÈÃδ¾­ÑéÖ¤µÄ¹¥»÷Õß·ÛËé²¢ÊÕÊÜMySQL Workbench¡£¡£¡£¡£¡£¡£¡£¡£Oracle MySQL8.0.17¼°ÒÔǰ°æ±¾Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£


Oracle Enterprise Manager| CVE-2016-4000


CVE-2016-4000ÊÇOracle Enterprise ManagerÖеÄÒ»¸ö·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬ËüÔÊÐíδ¾­ÑéÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâHTTPÒªÇóÒÔÆëÈ«ÊÕÊÜÒ×Êܹ¥»÷µÄÖ÷»ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ãȱµã´æÔÚÓÚOracleÆóÒµÖÎÀíÆ÷µÄJython×é¼þÖÐ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÊÐí¹¥»÷ÕßʹÓþ«ÐÄÔì×÷µÄÐòÁл¯PyType¶ÔÏóÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£


Oracle Construction and Engineering| CVE-2017-6056,CVE-2019-14379,CVE-2019-14379ºÍCVE-2019-3020


CVE-2017-6056ÓëInstantis EnterpriseÓÐ¹Ø £¬£¬£¬£¬£¬£¬£¬£¬ÆäÓàCVEÊÇPrimaveraÖз¢Ïֵķì϶¡£¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚÕâЩCVEÖеÄÿһ¸ö £¬£¬£¬£¬£¬£¬£¬£¬Î´¾­ÑéÖ¤µÄ¹¥»÷Õß¶¼Äܹ»ÏòÒ×Êܹ¥»÷µÄ×é¼þ·¢ËͶñÒâHTTPÒªÇó £¬£¬£¬£¬£¬£¬£¬£¬²¢ÆëÈ«ÊÕÊÜÊܹ¥»÷µÄÖ¸±ê»ò¶ÔÆäÖ´ÐÐÖÎÀí²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄPrimavera²úÆ·Ô̺¬Primavera P6¡¢Primavera GatewayºÍPrimavera Unifier¡£¡£¡£¡£¡£¡£¡£¡£


Oracle Middleware| CVE-2016-1000031ºÍCVE-2019-2904


CVE-2016-1000031ÊÇÔÚApacheCommonsÎļþÉÏ´«¿âÖз¢ÏÖµÄÔ¶³Ì´úÂëÖ´Ðзì϶ £¬£¬£¬£¬£¬£¬£¬£¬Oracle CPU¶ÔËü²¢²»Ä°Éú¡£¡£¡£¡£¡£¡£¡£¡£±¾Ô £¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÚOracle FusionÖÐÑë¼þµÄÐ鹹Ŀ¼·þÎñÆ÷×é¼þÖеõ½½¨²¹¡£¡£¡£¡£¡£¡£¡£¡£CVE×îÔçÊÇÓÉTenable ResearchÓÚ2016Äê·¢ÏÖµÄ £¬£¬£¬£¬£¬£¬£¬£¬¶ûºóÔÚ¶à¸öOracle²úÆ·ÖнøÐÐÁ˽¨²¹¡£¡£¡£¡£¡£¡£¡£¡£´ËÒ×Êܹ¥»÷µÄ·ì϶ÔÊÐí¹¥»÷ÕßʹÓÃHTTPÒªÇó·çÏÕOracleÐ鹹Ŀ¼¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-2904ÊÇOracle JDeveloperµÄADF Faces×é¼þºÍOracle FusionÖÐÑë¼þµÄADF²úÆ·ÖеÄÒ»¸öδָ¶¨·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»ÃèÊöΪ¡°Ò×ÓÚÀûÓá± £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓþ«ÐļÙÔìµÄhttpÒªÇó·çÏÕ²¢ÊÕÊÜoracle jdeveloperºÍadf¡£¡£¡£¡£¡£¡£¡£¡£


Oracle PeopleSoft| CVE-2016-0729,CVE-2019-3862


CVE-2016-0729ÊÇApacheXerces-CÖÐXML½âÎöÆ÷¿âÖеĶà¸ö¹Ø¼ü»º³åÇøÒç¶Âí½Å £¬£¬£¬£¬£¬£¬£¬£¬×î³õÊÇÔÚ2016Ä꽨²¹µÄ¡£¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶´æÔÚÓÚoracleÖеɴúÀíÖС£¡£¡£¡£¡£¡£¡£¡£Ëü¿ÉÄÜÔÊÐíδ¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔì³É»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-3862ÊÇLISSH2ÖеÄÒ»¸öÔ½½ç¶ÁÈ¡·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬Ô­ÒòÊÇÔÚSHSMSMSGCHANNELLÒªÇó°üÖÐûÓÐÕýÈ·µÄÍ˳ö״̬ÐÂÎŽâÎö¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÒÑÓÚ2019Äê3Ô½¨²¹¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚOracle PosioSoTµÄÎļþ´¦ÖÃÖ°ÄÜÖС£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.oracle.com/technetwork/topics/security/public-vuln-to-advisory-mapping-093627.html

https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html