¡¾Îó²îͨ¸æ¡¿Oracle 7Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-07-21

0x00 Îó²î¸ÅÊö

2021Äê7ÔÂ20ÈÕ£¬£¬£¬£¬£¬OracleÐû²¼ÁË7Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼Æ342¸ö£¬£¬£¬£¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Enterprise ManagerºÍOracle Fusion MiddlewareµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

Oracle Fusion Middleware¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË48¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ 35¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖаüÀ¨¶à¸öWebLogic ServerÇå¾²Îó²î£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOP»òT3ЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë»ò¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-2394¡¢CVE-2021-2397ºÍCVE-2021-2382£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£

 

Oracle Communications Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË33 ¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ 22 ¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2020-11612¡¢CVE-2021-3177¡¢CVE-2020-17530ºÍCVE-2019-17195£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£¡£¡£¡£

 

Oracle E-Business Suite¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË17 ¸öÊÊÓÃÓÚOracle E-Business Suite µÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ3¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2021-2355£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2021-2436¡¢CVE-2021-2359ºÍCVE-2021-2361ÔÚÄÚµÄ15¸ö¸ßΣÎó²î¡£¡£¡£¡£

 

Oracle Enterprise Manager¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË8 ¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÕâЩÎó²î¶¼¿ÉÒÔÔÚδ¾­ÓÉÉí·ÝÑéÖ¤µÄÇéÐÎÏÂÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2020-10683£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2019-5064ÔÚÄ򵀮äËü7¸öÇå¾²Îó²î¡£¡£¡£¡£

 

Oracle Financial Services Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË22¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÓÐ 17¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣡ£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2019-0228¡¢CVE-2021-26117¡¢CVE-2020-5413¡¢CVE-2020-11998ºÍCVE-2020-27218£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚOracleÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpujul2021.html

 

»º½â²½·¥

½ûÓÃT3ЭÒ飺

1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£¡£

2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£¡£

3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£¡£

image.png

 

½ûÓÃIIOPЭÒé:

Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

image.png

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpujul2021.html

https://us-cert.cisa.gov/ncas/current-activity/2021/07/20/oracle-releases-july-2021-critical-patch-update

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2394

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-21

Ê×´ÎÐû²¼

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚÈËÉú¾ÍÊDz©

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png       image.png