¡¾·ì϶¹«¸æ¡¿Oracle Scripting iSurveyÄ£¿éÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-30727)
°ä²¼¹¦·ò 2025-04-16Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Oracle Scripting iSurveyÄ£¿éÔ¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-30727 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-04-16 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Oracle ScriptingÊÇOracle E-Business SuiteÖеÄÒ»¸ö×é¼þ£¬ÓÃÓÚ´´½¨ºÍÖÎÀíÔÚÏßµ÷²é¡¢±íµ¥¼°¶¯Ì¬¾ç±¾¡£ËüÔÊÐíÆóҵͨ¹ý¿É¶¨ÔìµÄ¾ç±¾ÍøÂçÓû§Êý¾Ý£¬Ö§³ÖÒµÎñÁ÷³Ì×Ô¶¯»¯ºÍ¾ö²ßÖ§³Ö¡£Oracle ScriptingÌṩÁ˽ýݵÄÎʾíÉè¼Æ¹¤¾ß£¬¿ÉÄÜÓëÆäËûE-Business SuiteÄ£¿é¼¯³É£¬ÊµÏÖÊý¾ÝµÄ×Ô¶¯»¯ÍøÂçÓë´¦Ö᣸ÃÄ£¿é¿í·ºÀûÓÃÓÚ¿Í»§µ÷²é¡¢·´À¡ÍøÂç¡¢ºÏ¹æÐÔÆÀ¹ÀµÈ³¡¾°¡£
2025Äê4ÔÂ16ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Oracle°ä²¼µÄCVE-2025-30727°²È«²¼¸æ¡£²¼¸æÖ¸³ö£¬Oracle E-Business Suite µÄ Oracle Scripting ²úÆ·£¨×é¼þ£ºiSurvey Module£©´æÔÚÒ»ÏîÑϳÁ·ì϶£¬Î´ÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýHTTPÍøÂç½Ó¼ûÔ¶³ÌÀûÓø÷ì϶£¬¿ÉÄܵ¼ÖÂOracle ScriptingÔâµ½½ÚÔì¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷¿ÉÄܵ¼ÖÂOracle Scripting±»ÆëÈ«¹¥Ï¡£·ì϶ÆÀ·Ö9.8·Ö£¬·ì϶¼¶±ðΪÑϳÁ¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://www.oracle.com/security-alerts/cpuapr2025.html/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ