¡¾Â©¶´Í¨¸æ¡¿Oracle 7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-07-21

0x00 ©¶´¸ÅÊö

2021Äê7ÔÂ20ÈÕ£¬OracleÐû²¼ÁË7Ô·ݵÄÄþ¾²¸üУ¬±¾´ÎÐû²¼µÄÄþ¾²¸üй²¼Æ342¸ö£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Enterprise ManagerºÍOracle Fusion MiddlewareµÈ¶à¸ö²úÎïºÍ×é¼þ¡£

 

0x01 ©¶´ÏêÇé

image.png

Oracle Fusion Middleware¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË48¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ 35¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖаüÂÞ¶à¸öWebLogic ServerÄþ¾²Â©¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOP»òT3ЭÒé·¢ËͶñÒâÇëÇóÀ´ÀûÓÃÕâЩ©¶´£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë»ò¿ØÖÆ·þÎñÆ÷¡£ÑÏÖØÂ©¶´°üÂÞCVE-2021-2394¡¢CVE-2021-2397ºÍCVE-2021-2382£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£

 

Oracle Communications Applications¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË33 ¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÄþ¾²¸üУ¬ÆäÖÐÓÐ 22 ¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÑÏÖØÂ©¶´°üÂÞCVE-2021-21345¡¢CVE-2020-11612¡¢CVE-2021-3177¡¢CVE-2020-17530ºÍCVE-2019-17195£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´ÀûÓÃÕâЩ©¶´¡£

 

Oracle E-Business Suite¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË17 ¸öÊÊÓÃÓÚOracle E-Business Suite µÄÄþ¾²¸üУ¬ÆäÖÐÓÐ3¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄ©¶´ÎªCVE-2021-2355£¨CVSSÆÀ·ÖΪ9.1£©£¬¸Ã©¶´µÄÀûÓÃÅÓ´ó¶ÈµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£´ËÍ⣬Oracle»¹ÐÞ¸´Á˰üÂÞCVE-2021-2436¡¢CVE-2021-2359ºÍCVE-2021-2361ÔÚÄÚµÄ15¸ö¸ßΣ©¶´¡£

 

Oracle Enterprise Manager¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË8 ¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÄþ¾²¸üУ¬ÕâЩ©¶´¶¼¿ÉÒÔÔÚδ¾­¹ýÉí·ÝÑéÖ¤µÄÇé¿öÏÂÔ¶³ÌÀûÓá£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄ©¶´ÎªCVE-2020-10683£¨CVSSÆÀ·ÖΪ9.8£©£¬¸Ã©¶´µÄÀûÓÃÅÓ´ó¶ÈµÍ£¬ÇÒÎÞÐèÓû§½»»¥¡£´ËÍ⣬Oracle»¹ÐÞ¸´Á˰üÂÞCVE-2019-5064ÔÚÄ򵀮äËü7¸öÄþ¾²Â©¶´¡£

 

Oracle Financial Services Applications¶à¸öÄþ¾²Â©¶´

Oracle´Ë´Î¹²Ðû²¼ÁË22¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÄþ¾²¸üУ¬ÆäÖÐÓÐ 17¸ö©¶´ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÑÏÖØÂ©¶´°üÂÞCVE-2021-21345¡¢CVE-2019-0228¡¢CVE-2021-26117¡¢CVE-2020-5413¡¢CVE-2020-11998ºÍCVE-2020-27218£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´ÀûÓÃÕâЩ©¶´¡£

 

0x02 ´¦Öý¨Òé

ĿǰOracleÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÓû§¾¡¿ìÐÞ¸´¡£

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpujul2021.html

 

»º½â´ëÊ©

½ûÓÃT3ЭÒ飺

1£©½øÈëWebLogic¿ØÖÆÌ¨£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°Äþ¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£

2)ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£

3£©Éú´æºóÐèÖØÐÂÆô¶¯£¬¹æÔò·½¿ÉÉúЧ¡£

image.png

 

½ûÓÃIIOPЭÒé:

µÇ½WebLogic¿ØÖÆÌ¨£¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer

image.png

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpujul2021.html

https://us-cert.cisa.gov/ncas/current-activity/2021/07/20/oracle-releases-july-2021-critical-patch-update

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2394

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-21

Ê×´ÎÐû²¼

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png       image.png