¡¾·ì϶¹«¸æ¡¿Oracle 7Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-07-210x00 ·ì϶¸ÅÊö
2021Äê7ÔÂ20ÈÕ£¬£¬£¬£¬£¬Oracle°ä²¼ÁË7Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬±¾´Î°ä²¼µÄ°²È«¸üй²¼Æ342¸ö£¬£¬£¬£¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Enterprise ManagerºÍOracle Fusion MiddlewareµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

Oracle Fusion Middleware¶à¸ö°²È«·ì϶
OracleÕâ´Î¹²°ä²¼ÁË48¸öºÏÓÃÓÚOracle Fusion MiddlewareµÄ°²È«¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ 35¸ö·ì϶ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬¶à¸öWebLogic Server°²È«·ì϶£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýIIOP»òT3ºÍ̸·¢ËͶñÒâÒªÇóÀ´ÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë»ò½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£ÑϳÁ·ì϶Ô̺¬CVE-2021-2394¡¢CVE-2021-2397ºÍCVE-2021-2382£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£¡£¡£¡£
Oracle Communications Applications¶à¸ö°²È«·ì϶
OracleÕâ´Î¹²°ä²¼ÁË33 ¸öºÏÓÃÓÚ Oracle Communications Applications µÄ°²È«¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ 22 ¸ö·ì϶ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£ÆäÖÐÑϳÁ·ì϶Ô̺¬CVE-2021-21345¡¢CVE-2020-11612¡¢CVE-2021-3177¡¢CVE-2020-17530ºÍCVE-2019-17195£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýHTTPºÍ̸·¢ËͶñÒâÒªÇóÀ´ÀûÓÃÕâЩ·ì϶¡£¡£¡£¡£¡£¡£¡£
Oracle E-Business Suite¶à¸ö°²È«·ì϶
OracleÕâ´Î¹²°ä²¼ÁË17 ¸öºÏÓÃÓÚOracle E-Business Suite µÄ°²È«¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ3¸ö·ì϶ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶ΪCVE-2021-2355£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬£¬£¬¸Ã·ì϶µÄÀûÓø´ÔӶȵͣ¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Oracle»¹½¨¸´ÁËÔ̺¬CVE-2021-2436¡¢CVE-2021-2359ºÍCVE-2021-2361ÔÚÄÚµÄ15¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£¡£¡£
Oracle Enterprise Manager¶à¸ö°²È«·ì϶
OracleÕâ´Î¹²°ä²¼ÁË8 ¸öºÏÓÃÓÚOracle Enterprise ManagerµÄ°²È«¸üУ¬£¬£¬£¬£¬ÕâЩ·ì϶¶¼Äܹ»ÔÚδ¾¹ýÉí·ÝÑéÖ¤µÄÇé¿öÏÂÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶ΪCVE-2020-10683£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬£¬£¬¸Ã·ì϶µÄÀûÓø´ÔӶȵͣ¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Oracle»¹½¨¸´ÁËÔ̺¬CVE-2019-5064ÔÚÄ򵀮äËü7¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£
Oracle Financial Services Applications¶à¸ö°²È«·ì϶
OracleÕâ´Î¹²°ä²¼ÁË22¸öºÏÓÃÓÚOracle Financial Services ApplicationsµÄ°²È«¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ 17¸ö·ì϶ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£ÆäÖÐÑϳÁ·ì϶Ô̺¬CVE-2021-21345¡¢CVE-2019-0228¡¢CVE-2021-26117¡¢CVE-2020-5413¡¢CVE-2020-11998ºÍCVE-2020-27218£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýHTTPºÍ̸·¢ËͶñÒâÒªÇóÀ´ÀûÓÃÕâЩ·ì϶¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
ĿǰOracleÒѰ䲼Óйذ²È«¸üУ¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì½¨¸´¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpujul2021.html
»º½â´ëÊ©
½ûÓÃT3ºÍ̸£º
1£©½øÈëWebLogic½ÚÔį̀£¬£¬£¬£¬£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬½øÈëÏνÓɸѡÆ÷ÅäÖᣡ£¡£¡£¡£¡£¡£
2)ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û)¡£¡£¡£¡£¡£¡£¡£
3£©±£ÁôºóÐè³ÁÐÂÆô¶¯£¬£¬£¬£¬£¬¹æ¶¨·½¿ÉÉúЧ¡£¡£¡£¡£¡£¡£¡£

½ûÓÃIIOPºÍ̸:
µÇ½WebLogic½ÚÔį̀£¬£¬£¬£¬£¬base_domain >·þÎñÆ÷¸ÅÒª >AdminServer

0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpujul2021.html
https://us-cert.cisa.gov/ncas/current-activity/2021/07/20/oracle-releases-july-2021-critical-patch-update
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2394
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-07-21 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ