¡¾·ì϶¹«¸æ¡¿Oracle 1Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-01-20

0x00 ·ì϶¸ÅÊö

2021Äê01ÔÂ19ÈÕ£¬Oracle°ä²¼ÁË1Ô·ݵݲȫ¸üУ¬±¾´Î°ä²¼µÄ°²È«¸üй²¼Æ329¸ö£¬Éæ¼°Oracle E-Business Suite¡¢Fusion Middleware¡¢MySQL¡¢Database¡¢Java SE¡¢Oracle Construction and Engineering SuiteµÈ¶à¸ö²úÆ·ºÍ×é¼þ ¡£

 

0x01 ·ì϶ÏêÇé

image.png

²¿ÃÅ·ì϶ÁбíÈçÏ£º

Oracle E-Business Suite

CVE

²úÆ·

×é¼þ

CVSSÆÀ·Ö

ÑϳÁˮƽ

Ó°ÏìÁìÓò

CVE-2021-2029

Oracle Scripting

Miscellaneous

9.8

ÑϳÁ

12.1.1-12.1.3,   12.2.3-12.2.8

CVE-2021-2100

Oracle One-to-One   Fulfillment

Print Server

9.1

ÑϳÁ

12.1.1-12.1.3,   12.2.3-12.2.10

CVE-2021-2101

Oracle One-to-One   Fulfillment

Print Server

9.1

ÑϳÁ

12.1.1-12.1.3,   12.2.3-12.2.10

 

Oracle Fusion Middleware

CVE

²úÆ·

×é¼þ

CVSSÆÀ·Ö

ÑϳÁˮƽ

Ó°ÏìÁìÓò

CVE-2021-1994

Oracle WebLogic Server

Web Services

9.8

ÑϳÁ

10.3.6.0.0, 12.1.3.0.0

CVE-2021-2047

Oracle WebLogic Server

Core Components

9.8

ÑϳÁ

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0,   14.1.1.0.0

CVE-2021-2064

Oracle WebLogic Server

Core Components

9.8

ÑϳÁ

12.1.3.0.0

CVE-2021-2108

Oracle WebLogic Server

Core Components

9.8

ÑϳÁ

12.1.3.0.0

CVE-2021-2075

Oracle WebLogic Server

Samples

9.8

ÑϳÁ

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0,   14.1.1.0.0

CVE-2021-2109

Oracle WebLogic Server

Console

7.2

¸ßΣ

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0,   14.1.1.0.0

CVE-2019-17195

Oracle WebLogic Server

Core Components (Connect2id   Nimbus JOSE+JWT)

9.8

ÑϳÁ

12.2.1.3.0, 12.2.1.4.0

CVE-2019-10086

Oracle WebLogic Server

Console (Apache Commons   Beanutils)

7.3

¸ßΣ

10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0

 

Oracle MySQL

CVE

²úÆ·

×é¼þ

CVSSÆÀ·Ö

ÑϳÁˮƽ

Ó°ÏìÁìÓò

CVE-2021-2046

MySQL Server

Server: Stored Procedure

6.8

ÖÐΣ

8.0.22   and prior

CVE-2021-2020

MySQL Server

Server: Optimizer

6.5

ÖÐΣ

8.0.20   and prior

CVE-2021-2024

MySQL Server

Server: Optimizer

6.5

ÖÐΣ

8.0.22   and prior

 

WebLogic Server·´ÐòÁл¯·ì϶£¨CVE-2021-1994¡¢CVE-2021-2047¡¢CVE-2021-2064¡¢CVE-2021-2108¡¢CVE-2021-2075¡¢CVE-2019-17195ºÍCVE-2019-10086£©

ÕâЩ·ì϶ÊÇWeblogicÖеĶà¸ö·´ÐòÁл¯Â© ¡£¹¥»÷ÕßÄܹ»Í¨¹ýHTTP¡¢IIOP¡¢T3ºÍ̸·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß×îÖÕÄܹ»½ÚÔìWebLogic Server»òÔ¶³ÌÖ´ÐдúÂë ¡£

 

WebLogic ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-2109£©

¸Ã·ì϶´æÔÚÓÚWebLogic ServerµÄconsoleÖУ¬ÆäCVSSÆÀ·Ö7.2 ¡£¹¥»÷ÕßÄܹ»Í¨¹ýJNDI×¢Èë¹¥»÷À´Ô¶³ÌÖ´ÐкÅÁî»ò´úÂë ¡£

Ó°ÏìÁìÓò

10.3.6.0.0

12.1.3.0.0

12.2.1.3.0

12.2.1.4.0

14.1.1.0.0

 

0x02 ´ëÖý¨Òé

½¨Òé²Î¿¼Oracle¹Ù·½°ä²¼µÄ°²È«²¼¸æÉý¼¶ÖÁ×îа汾 ¡£

һʱ´ëÊ©

½ûÓÃT3ºÍ̸

¾ßÌå²Ù×÷£º

1£©½øÈëWebLogic½ÚÔį̀£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÏνÓɸѡÆ÷ÅäÖà ¡£

2)ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û) ¡£

3£©±£ÁôºóÐè³ÁÐÂÆô¶¯£¬¹æ¶¨·½¿ÉÉúЧ ¡£

image.png

 

 

½ûÓÃIIOPºÍ̸

µÇ½WebLogic½ÚÔį̀£¬base_domain >·þÎñÆ÷¸ÅÒª >AdminServer

image.png

 

 

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpujan2021.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1994

 

0x04 ¹¦·òÏß

2021-01-19  Oracle°ä²¼°²È«¸üÐÂ

2021-01-20  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png