¡¾Îó²îͨ¸æ¡¿Oracle 10Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-10-200x00 Îó²î¸ÅÊö
2021Äê10ÔÂ19ÈÕ£¬£¬£¬OracleÐû²¼ÁË10Ô·ݵÄÇå¾²¸üУ¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼Æ419¸ö£¬£¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Financial Services Applications¡¢Oracle Enterprise Manager¡¢Oracle Fusion Middleware¡¢Oracle Java SE¡¢Oracle MySQLºÍOracle SystemsµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£
0x01 Îó²îÏêÇé

l Oracle Fusion Middleware¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË38¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ 30¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£±¾´ÎÐû²¼µÄ¸üÐÂÉæ¼°¶à¸öOracle WebLogic ServerÎó²î£ºCVE-2021-35617¡¢CVE-2021-35620ºÍCVE-2021-35552µÈ£¬£¬£¬ÆäÖÐCVE-2021-35617µÄCVSSÆÀ·ÖΪ9.8£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPÐÒé¶ÔOracle WebLogic ServerÌᳫ¹¥»÷£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆOracle WebLogic Server¡£¡£¡£¡£
l Oracle Communications Applications¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË19¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ14¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-3177£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£
l Oracle E-Business Suite¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË18¸öÊÊÓÃÓÚOracle E-Business Suite µÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ4¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖаüÀ¨CVE-2021-35566¡¢CVE-2021-2483¡¢CVE-2021-35536ºÍCVE-2021-35585µÈ11¸ö¸ßΣÎó²î£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ8.1¡£¡£¡£¡£
l Oracle Enterprise Manager¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË8¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ5¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2021-26691£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£±ðµÄ£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2021-2137ºÍCVE-2021-29505ÔÚÄ򵀮äËü7¸öÇå¾²Îó²î¡£¡£¡£¡£
l Oracle Financial Services Applications¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË44¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ26¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2020-5413ºÍCVE-2020-10683£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£
l Oracle Java SE¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË15¸öÊÊÓÃÓÚOracle Java SEµÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ13¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖиßΣÎó²î°üÀ¨CVE-2021-3517¡¢CVE-2021-35560ºÍCVE-2021-27290¡£¡£¡£¡£ÆäÖУ¬£¬£¬CVE-2021-3517ºÍCVE-2021-35560Ó°ÏìÁËJava SE 8u301¡£¡£¡£¡£
l Oracle MySQL¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË66¸öÊÊÓÃÓÚOracle MySQLµÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ10¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-22931£¨Ó°ÏìMySQL¼¯Èº£©ºÍCVE-2021-3711£¨Ó°ÏìMySQL ЧÀÍÆ÷£©£¬£¬£¬Õâ2¸öÎó²îµÄCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£
l Oracle Systems¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË5¸öÊÊÓÃÓÚOracle SystemsµÄÇå¾²¸üУ¬£¬£¬ÆäÖÐÓÐ2¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-26691£¬£¬£¬ÆäCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£±ðµÄ£¬£¬£¬Oracle»¹Ðû²¼ÁËCVE-2021-35539¡¢CVE-2021-35589¡¢CVE-2021-35549ºÍCVE-2020-1968µÈ¶à¸öÎó²îµÄ²¹¶¡¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚOracleÒѾÐû²¼ÁËÏà¹Ø²¹¶¡£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£¡£
Îó²îÁÐ±í¼°Ó°Ïì¹æÄ£Çë²Î¿¼Oracle¹Ù·½Í¨¸æ£º
https://www.oracle.com/security-alerts/cpuoct2021.html
»º½â²½·¥
Õë¶ÔWebLogic£¬£¬£¬½¨Òé½ûÓÃT3ÐÒé»òIIOPÐÒé¡£¡£¡£¡£
½ûÓÃT3ÐÒ飬£¬£¬Ïêϸ²Ù×÷£º
1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£¡£
2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£¡£
3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£¡£

½ûÓÃIIOPÐÒ飬£¬£¬Ïêϸ²Ù×÷£º
Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpuoct2021.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22931
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-10-20 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ