Oracle | 10Ô¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-10-21

0x00 ·ì϶¸ÅÊö

2020Äê10ÔÂ20ÈÕ £¬Oracle°ä²¼10Ô·ݵݲȫ¸üР£¬½¨¸´Á˶à¸ö²úÆ·Öеݲȫ·ì϶¡£Õâ´Î°ä²¼µÄ·ì϶²¹¶¡¹²¼Æ402¸ö £¬ÖØÒªÉæ¼°Oracle Database Server¡¢Oracle Communications¡¢Oracle Fusion Middleware¡¢Oracle Weblogic¡¢Oracle E-Business SuiteºÍOracle MySQLµÈ²úÆ· £¬ÆäÖжà¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ¡£

 

0x01 ·ì϶ÏêÇé

 

image.png

 

Oracle Database Server

Õâ´Î¸üÐÂÖÐÔ̺¬OracleÊý¾Ý¿âµÄ18¸öµÄ°²È«²¹¶¡¡£ÆäÖÐÓÐ4¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º

·ì϶±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2020-13935

Workload Manager (Apache Tomcat)

None

7.5

12.2.0.1, 18c, 19c

CVE-2020-14734

Oracle Text

None

8.1

11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c

CVE-2020-14735

Scheduler

Local Logon

8.8

11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c

 

 

Oracle Communications¼° Oracle Communications Applications

Õâ´Î¸üÐÂÖÐÔ̺¬Oracle CommunicationsµÄ52¸öµÄ°²È«²¹¶¡ºÍ9¸öOracle Communications Applications°²È«²¹¶¡ £¬ÆäÖÐÓÐ41¸öOracle Communications·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º

·ì϶±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2020-2555

Oracle WebCenter Portal

Database Module (Oracle Coherence)

9.8

12.2.1.3.0 £¬

12.2.1.4.0

CVE-2020-10683

Oracle Communications Unified Inventory Management

Core (dom4j)

9.8

7.3.0 £¬7.4.0

CVE-2020-10878

Oracle Communications Billing and Revenue Management

Core (Perl)

8.6

12.0.0.2.0 £¬ 12.0.0.3.0

CVE-2020-11973

Oracle Communications Diameter Signaling Router (DSR)

IDIH (Apache Camel)

9.8

IDIH: 8.0.0-8.2.2

CVE-2020-11984

Oracle Communications Element Manager

Core (Apache HTTP Server)

9.8

8.2.0-8.2.2

 

 

Oracle Fusion Middleware

Õâ´Î¸üÐÂÖÐÔ̺¬Oracle Fusion MiddlewareµÄ46¸ö°²È«²¹¶¡¡£ÆäÖÐÓÐ36¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÉæ¼°Á˶à¸öWeblogic·´ÐòÁл¯·ì϶ £¬ÕâЩ·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýHTTP¡¢IIOP¡¢T3ºÍ̸·¢ËͶñÒâÒªÇó £¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë¡£²¿ÃÅÑϳÁ·ì϶ÈçÏ£º

·ì϶±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2020-14820

Oracle WebLogic Server

Core

7.5

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14825

Oracle WebLogic Server

Core

9.8

12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14841

Oracle WebLogic Server

Core

9.8

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14859

Oracle WebLogic Server

Core

9.8

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

CVE-2020-14882

Oracle WebLogic Server

Console

9.8

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

 

 

Oracle E-Business Suite

Õâ´Î¸üÐÂÔ̺¬Oracle E-Business SuiteµÄ27¸ö°²È«²¹¶¡¡£ÆäÖеÄ25¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º

·ì϶±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2020-14805

Oracle E-Business Suite Secure Enterprise Search

Search Integration Engine

9.1

12.1.3, 12.2.3 - 12.2.10

CVE-2020-14855

Oracle Universal Work Queue

Work Provider Administration

9.8

12.1.3

CVE-2020-14862

Oracle Universal Work Queue

Internal Operations

8.8

12.2.3 - 12.2.9

CVE-2020-14875

Oracle Marketing

Marketing Administration

9.1

12.1.1 - 12.1.3, 12.2.3 - 12.2.10

CVE-2020-14876

Oracle Trade Management

User Interface

9.1

12.1.1 - 12.1.3, 12.2.3 - 12.2.10

 

 

Oracle MySQL

Õâ´Î¸üÐÂÖÐÔ̺¬Oracle MysqlµÄ54¸öµÄ°²È«²¹¶¡¡£ÆäÖÐÓÐ4¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º

·ì϶±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2020-8174

MySQL Cluster

Cluster: JS module (Node.js)

9.8

7.3.30 and prior,

7.4.29 and prior,

7.5.19 and prior,

7.6.15 and prior,

8.0.21 and prior

CVE-2020-13935

MySQL Enterprise Monitor

Monitoring: General (Apache Tomcat)

7.5

8.0.21 and prior

CVE-2020-14878

MySQL Server

Server: Security: LDAP Auth

8.0

8.0.21 and prior

 

´Ë±í £¬ÔÚ±¾´Î°ä²¼µÄ¶à¸ö°²È«·ì϶Öл¹Ô̺¬2¸öÆÀ·ÖΪ10£¨Âú·Ö10·Ö£©µÄ·ì϶ £¬ÈçÏ£º

·ì϶±àºÅ

²úÆ·

×é¼þ

ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2020-1953

Oracle Healthcare Foundation

Self Service Analytics (Apache Commons Configuration)

10.0

7.1.1 £¬7.2.0 £¬7.2.1 £¬7.3.0

CVE-2020-14871

Oracle Solaris

Pluggable authentication module

10.0

10 £¬11

 

Oracle Healthcare Foundation Self Service Analytics·ì϶£¨CVE-2020-1953£©

¸Ã·ì϶ÊÇÓÉÓÚOracle Healthcare FoundationµÄ×ÔÖ÷·ÖÎö·þÎñ£¨Apache Commons Configuration£©Ê¹ÓõÚÈý·½¿âÀ´½âÎöYAMLÎļþ £¬ÈôÊÇYAMLÔ̺¬ÌØÊâÓï¾ä £¬ÔòĬÈÏÇé¿öÏÂËüÔÊÐíÊ·ý»¯Àà¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓÕµ¼Óû§´Ó²»ÊÜÐÅÀµµÄÔ´¼ÓÔØYAMLÎļþÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚÖ÷»úÀûÓ÷¨Ê½µÄ½ÚÔìÁìÓòÖ®±í¼ÓÔØ²¢Ö´ÐдúÂë¡£

Ó°ÏìÁìÓò£º

Apache Commons Configuration2.2 £¬2.3 £¬2.4 £¬2.5 £¬2.6

Oracle Healthcare Foundation 7.1.1 £¬7.2.0 £¬7.2.1 £¬7.3.0

²Î¿¼Á´½Ó£º

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1953

 

Oracle Solaris Pluggable authentication module·ì϶(CVE-2020-14871)

¸Ã·ì϶µÄϸ½ÚÁÙʱδ¹«¿ª¡£

Ó°ÏìÁìÓò£º

Oracle Solaris10 £¬11

²Î¿¼Á´½Ó£º

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14871

 

0x02 ´ëÖý¨Òé

½¨Òé²Î¿¼¹Ù·½°ä²¼µÄ²¹¶¡¸üÐÂÐÅϢʵʱ½¨¸´»òÉý¼¶ÖÁ°²È«°æ±¾¡£

Á´½ÓµØÖ·£º

https://www.oracle.com/security-alerts/cpuoct2020.html

ÏÂÔØµØÖ·£º

https://www.oracle.com/cn/downloads/

ÆäËü´ëÊ©£º

ÈôÊDz»ÒÀÀµT3ºÍ̸ºÍIIOPºÍ̸½øÐÐJVMͨѶ £¬Ôò½¨Òé½ûÓá£

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuoct2020.html

https://www.oracle.com/security-alerts/

https://us-cert.cisa.gov/ncas/current-activity/2020/10/20/oracle-releases-october-2020-security-bulletin-0

 

0x04 ¹¦·òÏß

2020-10-20  Oracle°ä²¼°²È«¸üÐÂ

2020-10-21  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 

image.png