¡¾Îó²îͨ¸æ¡¿Oracle 10Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-10-20

0x00 Îó²î¸ÅÊö

2021Äê10ÔÂ19ÈÕ£¬£¬£¬£¬£¬OracleÐû²¼ÁË10Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼Æ419¸ö£¬£¬£¬£¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Financial Services Applications¡¢Oracle Enterprise Manager¡¢Oracle Fusion Middleware¡¢Oracle Java SE¡¢Oracle MySQLºÍOracle SystemsµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£ ¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

l  Oracle Fusion Middleware¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË38¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ 30¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£±¾´ÎÐû²¼µÄ¸üÐÂÉæ¼°¶à¸öOracle WebLogic ServerÎó²î£ºCVE-2021-35617¡¢CVE-2021-35620ºÍCVE-2021-35552µÈ£¬£¬£¬£¬£¬ÆäÖÐCVE-2021-35617µÄCVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£ ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPЭÒé¶ÔOracle WebLogic ServerÌᳫ¹¥»÷£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆOracle WebLogic Server¡£ ¡£¡£¡£¡£¡£


l  Oracle Communications Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË19¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ14¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-3177£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£ ¡£¡£¡£¡£¡£

 

l  Oracle E-Business Suite¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË18¸öÊÊÓÃÓÚOracle E-Business Suite µÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ4¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£ÆäÖаüÀ¨CVE-2021-35566¡¢CVE-2021-2483¡¢CVE-2021-35536ºÍCVE-2021-35585µÈ11¸ö¸ßΣÎó²î£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ8.1¡£ ¡£¡£¡£¡£¡£

 

l  Oracle Enterprise Manager¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË8¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ5¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2021-26691£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2021-2137ºÍCVE-2021-29505ÔÚÄ򵀮äËü7¸öÇå¾²Îó²î¡£ ¡£¡£¡£¡£¡£

 

l  Oracle Financial Services Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË44¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ26¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2020-5413ºÍCVE-2020-10683£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£ ¡£¡£¡£¡£¡£

 

l  Oracle Java SE¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË15¸öÊÊÓÃÓÚOracle Java SEµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ13¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£ÆäÖиßΣÎó²î°üÀ¨CVE-2021-3517¡¢CVE-2021-35560ºÍCVE-2021-27290¡£ ¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬CVE-2021-3517ºÍCVE-2021-35560Ó°ÏìÁËJava SE 8u301¡£ ¡£¡£¡£¡£¡£

 

l  Oracle MySQL¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË66¸öÊÊÓÃÓÚOracle MySQLµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ10¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-22931£¨Ó°ÏìMySQL¼¯Èº£©ºÍCVE-2021-3711£¨Ó°ÏìMySQL ЧÀÍÆ÷£©£¬£¬£¬£¬£¬Õâ2¸öÎó²îµÄCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£ ¡£¡£¡£¡£¡£

 

l  Oracle Systems¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË5¸öÊÊÓÃÓÚOracle SystemsµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ2¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-26691£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Oracle»¹Ðû²¼ÁËCVE-2021-35539¡¢CVE-2021-35589¡¢CVE-2021-35549ºÍCVE-2020-1968µÈ¶à¸öÎó²îµÄ²¹¶¡¡£ ¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚOracleÒѾ­Ðû²¼ÁËÏà¹Ø²¹¶¡£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üС£ ¡£¡£¡£¡£¡£

Îó²îÁÐ±í¼°Ó°Ïì¹æÄ£Çë²Î¿¼Oracle¹Ù·½Í¨¸æ£º

https://www.oracle.com/security-alerts/cpuoct2021.html

 

»º½â²½·¥

Õë¶ÔWebLogic£¬£¬£¬£¬£¬½¨Òé½ûÓÃT3ЭÒé»òIIOPЭÒé¡£ ¡£¡£¡£¡£¡£

½ûÓÃT3ЭÒ飬£¬£¬£¬£¬Ïêϸ²Ù×÷£º

1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣠ¡£¡£¡£¡£¡£

2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£ ¡£¡£¡£¡£¡£

3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£ ¡£¡£¡£¡£¡£

image.png

 

½ûÓÃIIOPЭÒ飬£¬£¬£¬£¬Ïêϸ²Ù×÷£º

Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

image.png

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuoct2021.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22931

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-10-20

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚÈËÉú¾ÍÊDz©

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png