ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ29ÖÜ

°ä²¼¹¦·ò 2020-07-20

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê07ÔÂ13ÈÕÖÁ07ÔÂ19ÈÕ¹²ÊÕ¼°²È«·ì϶82¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç¶Âí½Å£»£»£»£»£» £»Oracle Fusion Middleware WebLogic Server CVE-2020-14625ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£» £»Oracle GoldenGate Process Management×é¼þ´úÂëÖ´Ðзì϶£»£»£»£»£» £»Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´Ðзì϶; ABB IRC5 OPCĬÈÏÓ²±àÂë·ì϶¡£¡£¡£¡£¡£ ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇVMware½¨¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ·ì϶£»£»£»£»£» £»ºÚ¿ÍÈëÇÖ°²È«¹«Ë¾DataViper·þÎñÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢£»£»£»£»£» £»SAP°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´NetWeaverÖеÄÑϳÁ·ì϶£»£»£»£»£» £»ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý£»£»£»£»£» £»Ë¼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£ ¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£ ¡£¡£



>³ÁÒª°²È«·ì϶Áбí


1.Microsoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç¶Âí½Å


Microsoft Windows Server DNS Server´¦ÖÃÏìÓ¦²ÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1350


2. Oracle Fusion Middleware WebLogic Server CVE-2020-14625ËÁÒâ´úÂëÖ´Ðзì϶


Oracle Fusion Middleware WebLogic Server´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://www.oracle.com/security-alerts/cpujul2020.html


3. Oracle GoldenGate Process Management×é¼þ´úÂëÖ´Ðзì϶


Oracle GoldenGate Process Management×é¼þ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://www.oracle.com/security-alerts/cpujul2020.html


4. Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´Ðзì϶


Adobe Media Encoder´¦ÖÃÒôƵÎļþ´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://helpx.adobe.com/security/products/media-encoder/apsb20-36.html


5. ABB IRC5 OPCĬÈÏÓ²±àÂë·ì϶


ABB IRC5 OPC server´æÔÚĬÈÏÓ²±àÂë·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼ûϵͳ¡£¡£¡£¡£¡£ ¡£¡£

https://github.com/aliasrobotics/RVD/issues/3326



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢VMware½¨¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/10/vmware-releases-security-updates-multiple-products


2¡¢ºÚ¿ÍÈëÇÖ°²È«¹«Ë¾DataViper·þÎñÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-breaches-security-firm-in-act-of-revenge/#ftag=RSSbaffb68


3¡¢SAP°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´NetWeaverÖеÄÑϳÁ·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/alerts/aa20-195a


4¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/


5¡¢Ë¼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´´úÂëÖ´Ðзì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products