OracleÊý¾Ý¿âJavaÐé¹¹»ú·ì϶

°ä²¼¹¦·ò 2018-08-13

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-3110£¬¸ßΣ£¬³§ÉÌ×ÔÆÀ£º9.9£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


OracleÊý¾Ý¿â 18c£¬OracleÊý¾Ý¿âWindows°æ11.2.0.4Óë12.2.0.1£¬Í¬Ê±¶Ôȫƽ̨12.1.0.2ÇÒδÀûÓÃ2018Äê7ÔÂCPUµÄ°æ±¾Ò²»á²úÉúÓ°Ï죬Àϰ汾ºÜ¿ÉÄܾù»áÊܵ½ÆäÓ°Ïì¡£


·ì϶¸ÅÊö

2018Äê8ÔÂ10ÈÕ£¬Oracle°ä²¼°²È«¹«¸æ£¬¶ÔOracleÊý¾Ý¿â·þÎñÆ÷ÖÐJavaÐé¹¹»ú´æÔڵķì϶CVE-2018-3110½øÐÐÁËÔ¤¾¯¡£´Ë·ì϶CVSSÆÀ·ÖΪ9.9·Ö£¬Ó°Ïì½ÏΪÑϳÁ£¬Óû§Ó¦ÊµÊ±½øÐиüС£´Ë·ì϶Óë2018Äê7Ô°䲼µÄCPUÖеÄCVE-2018-3004ͬԴ£¬¹¥»÷·½Ê½¸üΪ¼ò»¯¡£´Ë·ì϶»á±»¹¥»÷ÕßÀûÓÃͨ¹ýOracle Net¹¥»÷JavaÐé¹¹»ú£¬¹ÌÈ»´Ë·ì϶´æÔÚÓÚJavaÐé¹¹»úÖУ¬µ«¿É±»ÀûÓÃÀ´¹¥»÷ÆäËûµÄ²úÆ·Óë·þÎñ¡£¹¥»÷Õß¹¥»÷³É¹¦ºó¿ÉÊÕÊÜÕû¸öJavaÐé¹¹»ú¡£Õâ¸ö·ì϶ÊDZØÒªÇ°ÌáǰÌáµÄ£¬CVE-2018-3110 ±ØÒªÒ»¸öÊý¾Ý¿âÓû§£¬¾ß±¸×î¸ù»ùµÄCREATE SESSION£¬Ò²¾ÍÊÇ˵¿ÉÄÜ´´½¨»á»°£¬Ïνӵ½Êý¾Ý¿â¡£¶øºó£¬»ùÓÚ¶ÔÓÚ¹«¹² JAVA ¶ÔÏóµÄ½Ó¼û£¬»ñµÃȨÏÞÌáÉý£¬Ö±ÖÁÈ«Êý½ÚÔìÊý¾Ý¿â¡£


½¨¸´½¨Òé


ÏÂΪ¹Ù·½¹«¸æÖÐÊÜÓ°Ïì²úÆ·¼°²¹¶¡¿ÉÓÃÐÔÎĵµ£º

Affected Products and Versions

Patch Availability Document

Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18

Database



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 

·ì϶²¹¶¡½öºÏÓÃÓÚÕ¼ÓÐPremier SupportÒÔ¼°Extended Support·þÎñµÄ²úÆ·£¬²»ÔÚ´ËÁеIJúÆ·²¢Î´²âÊÔÊÇ·ñ»áÊܵ½´Ë·ì϶ӰÏ죬µ«ÊÇÈÔ¾ÉÍÆ¼öÓû§Éý¼¶µ½¸ü¸ß¼¶µÄ·þÎñÒÔ»ñÈ¡°²È«²¹¶¡¡£


²Î¿¼Á´½Ó


http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.html
https://nvd.nist.gov/vuln/detail/CVE-2018-3110