Oracle 4Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-04-21

0x00 ·ì϶¸ÅÊö

2021Äê04ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬Oracle°ä²¼ÁË4Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬£¬±¾´Î°ä²¼µÄ°²È«²¹¶¡¹²¼Æ390¸ö£¬£¬£¬£¬£¬£¬Éæ¼°Oracle Fusion Middleware¡¢Oracle E-Business Suite¡¢Oracle Communications ApplicationsºÍOracle MySQLµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

ÔÚ±¾´Î°ä²¼µÄ°²È«²¹¶¡ÖУ¬£¬£¬£¬£¬£¬Oracle Fusion MiddlewareÓйصIJ¹¶¡Îª45¸ö£¬£¬£¬£¬£¬£¬ÆäÖÐ36¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£¡£Weblogic Server²¿ÃÅ·ì϶ÏêÇéÈçÏ£º

Oracle WebLogic Server Coherence Container°²È«·ì϶£¨CVE-2021-2135£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýT3»òIIOPºÍ̸·¢ËͶñÒâÒªÇ󣬣¬£¬£¬£¬£¬×îÖÕ½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓ㬣¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò

12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0

 

Oracle WebLogic Server Core°²È«·ì϶£¨CVE-2021-2136£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýIIOPºÍ̸·¢ËͶñÒâÒªÇ󣬣¬£¬£¬£¬£¬×îÖÕ½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓ㬣¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò

12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0

 

Oracle WebLogic Server TopLink Integration°²È«·ì϶£¨CVE-2021-2157£©

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýHTTP·¢ËͶñÒâÒªÇ󣬣¬£¬£¬£¬£¬×îÖÕÄܹ»Î´ÊÚȨ½Ó¼û¹Ø¼üÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓ㬣¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò

10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0

 

´Ë±í£¬£¬£¬£¬£¬£¬ÔÚOracle±¾´Î°ä²¼µÄ°²È«²¹¶¡ÖУº

ÓëOracle Communications ApplicationsÓйصIJ¹¶¡Îª13¸ö£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2020-11612ºÍCVE-2020-28052ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓÃÔ̺¬Õâ2¸ö·ì϶ÔÚÄÚµÄ12¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£

ÓëE-Business SuiteÓйصIJ¹¶¡Îª70¸ö£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2021-2200ºÍCVE-2021-2205ÆÀ·ÖΪ9.1£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓÃÔ̺¬Õâ2¸ö·ì϶ÔÚÄÚµÄ22¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£

ÓëOracle MySQLÓйصIJ¹¶¡Îª49¸ö£¬£¬£¬£¬£¬£¬ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓõķì϶Ϊ10¸ö£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2021-3449ºÍCVE-2021-3450£¨¾ùΪMySQL ServerÖеÄOpenSSLÎÊÌ⣩ÆÀ·Ö±ðÀëΪ7.5ºÍ7.4, CVE-2021-2307ΪMySQL for WindowsÖеÄȨÏÞÌáÉý·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶Ðè¾­¹ýÑéÖ¤ÄÜÁ¦ÀûÓ㬣¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ6.1¡£¡£¡£¡£¡£¡£¡£¡£

 

0x02 ´ëÖý¨Òé

ĿǰOracleÒѾ­°ä²¼Óйذ²È«²¹¶¡£¬£¬£¬£¬£¬£¬½¨Ò龡¿ìÀûÓᣡ£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2021.html

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuapr2021.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2135

https://kb.cert.org/vuls/id/567764

 

0x04 ¹¦·òÏß

2021-04-20  Oracle°ä²¼°²È«¸üÐÂ

2021-04-21  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png