¡¾Îó²îͨ¸æ¡¿Oracle 7Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-07-210x00 Îó²î¸ÅÊö
2021Äê7ÔÂ20ÈÕ£¬OracleÐû²¼ÁË7Ô·ݵÄÇå¾²¸üУ¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼Æ342¸ö£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Enterprise ManagerºÍOracle Fusion MiddlewareµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£
0x01 Îó²îÏêÇé

Oracle Fusion Middleware¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË48¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÇå¾²¸üУ¬ÆäÖÐÓÐ 35¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓá£ÆäÖаüÀ¨¶à¸öWebLogic ServerÇå¾²Îó²î£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOP»òT3ÐÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë»ò¿ØÖÆ·þÎñÆ÷¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-2394¡¢CVE-2021-2397ºÍCVE-2021-2382£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£
Oracle Communications Applications¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË33 ¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÇå¾²¸üУ¬ÆäÖÐÓÐ 22 ¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓá£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2020-11612¡¢CVE-2021-3177¡¢CVE-2020-17530ºÍCVE-2019-17195£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPÐÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£
Oracle E-Business Suite¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË17 ¸öÊÊÓÃÓÚOracle E-Business Suite µÄÇå¾²¸üУ¬ÆäÖÐÓÐ3¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓá£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2021-2355£¨CVSSÆÀ·ÖΪ9.1£©£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£±ðµÄ£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2021-2436¡¢CVE-2021-2359ºÍCVE-2021-2361ÔÚÄÚµÄ15¸ö¸ßΣÎó²î¡£
Oracle Enterprise Manager¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË8 ¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÇå¾²¸üУ¬ÕâЩÎó²î¶¼¿ÉÒÔÔÚδ¾ÓÉÉí·ÝÑéÖ¤µÄÇéÐÎÏÂÔ¶³ÌʹÓá£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2020-10683£¨CVSSÆÀ·ÖΪ9.8£©£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£±ðµÄ£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2019-5064ÔÚÄ򵀮äËü7¸öÇå¾²Îó²î¡£
Oracle Financial Services Applications¶à¸öÇå¾²Îó²î
Oracle´Ë´Î¹²Ðû²¼ÁË22¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÇå¾²¸üУ¬ÆäÖÐÓÐ 17¸öÎó²îÎÞÐè¾ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓá£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2019-0228¡¢CVE-2021-26117¡¢CVE-2020-5413¡¢CVE-2020-11998ºÍCVE-2020-27218£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPÐÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚOracleÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÓû§¾¡¿ìÐÞ¸´¡£
ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpujul2021.html
»º½â²½·¥
½ûÓÃT3ÐÒ飺
1£©½øÈëWebLogic¿ØÖÆÌ¨£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖá£
2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£
3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£

½ûÓÃIIOPÐÒé:
Éϰ¶WebLogic¿ØÖÆÌ¨£¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer

0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpujul2021.html
https://us-cert.cisa.gov/ncas/current-activity/2021/07/20/oracle-releases-july-2021-critical-patch-update
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2394
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-21 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ×ðÁú¿Ê±
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ