ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ29ÖÜ
°ä²¼¹¦·ò 2020-07-20> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê07ÔÂ13ÈÕÖÁ07ÔÂ19ÈÕ¹²ÊÕ¼°²È«·ì϶82¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»Oracle Fusion Middleware WebLogic Server CVE-2020-14625ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Oracle GoldenGate Process Management×é¼þ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´Ðзì϶; ABB IRC5 OPCĬÈÏÓ²±àÂë·ì϶¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇVMware½¨¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ·ì϶£»£»£»£»£»£»ºÚ¿ÍÈëÇÖ°²È«¹«Ë¾DataViper·þÎñÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢£»£»£»£»£»£»SAP°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´NetWeaverÖеÄÑϳÁ·ì϶£»£»£»£»£»£»ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý£»£»£»£»£»£»Ë¼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1.Microsoft Windows Server DNS Server CVE-2020-1350»º³åÇøÒç¶Âí½Å
Microsoft Windows Server DNS Server´¦ÖÃÏìÓ¦²ÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1350
2. Oracle Fusion Middleware WebLogic Server CVE-2020-14625ËÁÒâ´úÂëÖ´Ðзì϶
Oracle Fusion Middleware WebLogic Server´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.oracle.com/security-alerts/cpujul2020.html
3. Oracle GoldenGate Process Management×é¼þ´úÂëÖ´Ðзì϶
Oracle GoldenGate Process Management×é¼þ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.oracle.com/security-alerts/cpujul2020.html
4. Adobe Media Encoder CVE-2020-9650Ô½½çд´úÂëÖ´Ðзì϶
Adobe Media Encoder´¦ÖÃÒôƵÎļþ´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb20-36.html
5. ABB IRC5 OPCĬÈÏÓ²±àÂë·ì϶
ABB IRC5 OPC server´æÔÚĬÈÏÓ²±àÂë·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼ûϵͳ¡£¡£¡£¡£¡£¡£¡£
https://github.com/aliasrobotics/RVD/issues/3326
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢VMware½¨¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ·ì϶
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/10/vmware-releases-security-updates-multiple-products
2¡¢ºÚ¿ÍÈëÇÖ°²È«¹«Ë¾DataViper·þÎñÆ÷ÇÔÈ¡ÊýÊ®ÒÚÓû§ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-breaches-security-firm-in-act-of-revenge/#ftag=RSSbaffb68
3¡¢SAP°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´NetWeaverÖеÄÑϳÁ·ì϶
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/alerts/aa20-195a
4¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ªwattpadµÄ2.7ÒÚÌõÓû§Êý¾Ý
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/wattpad-data-breach-exposes-account-info-for-millions-of-users/
5¡¢Ë¼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´´úÂëÖ´Ðзì϶
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products


¾©¹«Íø°²±¸11010802024551ºÅ