Oracleȫϵ²úÆ·2019Äê10Ô¹ؼü²¹¶¡¸üа²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-17

·ì϶¸ÅÊö


10ÔÂ15ÈÕ£¬Oracle°ä²¼ÁË2019Äê10ÔµĹؼü²¹¶¡¸üУ¨CPU£©£¬×÷Ϊ¼¾¶È·ì϶½¨¸´°ä²¼µÄÒ»²¿ÃÅ¡£´Ë¸üÐÂÔ̺¬¶à¸öOracle²úÆ·ÖÐ219¸ö²¹¶¡ÖÐ180¸öCVEµÄ½¨¸´·¨Ê½¡£Éæ¼°Oracle Enterprise manager Products Suite¡¢Oracle Fusion Middleware¡¢Oracle Knowledge¡¢Oracle MySQLµÈ¶à¸ö²úÆ·¡£


ÆäÖÐWeblogic Serve´æÔÚ¶à¸ö¸ßΣ·ì϶


Oracle WebLogic Server| CVE-2019-2887, CVE-2019-2890, CVE-2019-2891


CVE-2019-2887ÓëCVE-2019-2890µ¼Ö¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷£¬½ûÓÃT3ºÍ̸²Ù×÷·½Ê½½øÐзÀ»¤¿É²Î¿¼Á´½Óhttps://mp.weixin.qq.com/s/YWTSyEVunQUordwxThrGwA¡£


CVE-2019-2891¿Éµ¼Ö¹¥»÷ÕßÄÜ·¢ËÍHTTPÒªÇó¹¥»÷WebLogic Server¡£


´Ë±í»¹ÓÐÒÔÏÂWebLogic Server·ì϶±ØÒª½øÐйØ×¢£ºCVE-2019-2888£¬CVE-2019-2889£¬CVE-2015-9251£¬CVE-2019-11358£¬CVE-2019-17091¡£


±¾¼¾¶ÈµÄCPU»¹Ô̺¬18¸öCVSS 9+·ì϶£»ÀûÓÃÕâЩ·ì϶¿ÉÄܵ¼ÖÂδ¾­ÑéÖ¤µÄ½Ó¼û»òÆëÈ«ÊÕÊÜÒ×Êܹ¥»÷µÄ×ʲú¡£


CVE#

Product

BaseScore

CVE-2018-14721

Oracle NoSQL Database

10

CVE-2017-6056

Instantis EnterpriseTrack

9.8

CVE-2019-14379

Primavera Gateway

9.8

CVE-2019-14379

Primavera Unifier

9.8

CVE-2019-3020

Primavera P6 Enterprise Project Portfolio Management

9.3

CVE-2016-4000

Enterprise Manager Base Platform

9.8

CVE-2019-14379

Oracle Banking Platform

9.8

CVE-2019-14379

Oracle Financial Services Analytical Applications Infrastructure

9.8

CVE-2019-2904

Oracle JDeveloper and ADF

9.8

CVE-2016-1000031

Oracle Virtual Directory

9.8

CVE-2017-5645

JD Edwards EnterpriseOne Tools

9.8

CVE-2019-8457

MySQL Workbench

9.8

CVE-2016-0729

PeopleSoft Enterprise PeopleTools

9.8

CVE-2019-3862

PeopleSoft Enterprise PeopleTools

9.1

CVE-2018-19362

MICROS Retail XBRi Loss Prevention

9.8

CVE-2019-14379

Oracle Retail Xstore Point of Service

9.8

CVE-2018-1000007

Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers

9.8

CVE-2016-6814

Agile Recipe Management for Pharmaceuticals

9.8



ÕâÀïÎÒÃǸü¾ßÌ嵨ÃèÊöÁËһЩCVSS 9+ÆÀ·ÖCVE£º


Oracle NoSQLÊý¾Ý¿â| CVE-2018-14721


±¾ÔÂ×îÖµÍ×ÌùÐĵIJ¹¶¡Ö®Ò»½â¾öÁËCVE-2018-14721£¬ÕâÊÇOracle NoSQLÊý¾Ý¿âÖÐÓ°Ïì19.3.12֮ǰËùÓа汾µÄ·ì϶¡£¸Ã·ì϶´æÔÚÓÚJackson DATABONE NOSQL×é¼þÄÚ¡£Í¨¹ýHTTP½øÐÐÍøÂç½Ó¼ûµÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÊÕÊÜOracle NoSQLÊý¾Ý¿â¡£´Ë·ì϶ÒÔǰÔÚÆäËûOracle²úÆ·£¨Ô̺¬Oracle 2019Äê1ÔµÄCPU£©ÖÐÒѵõ½½â¾ö¡£


Oracle MySQL| CVE-2019-8457


CVE-2019-8457ÊÇOracle MySQLµÄsqlite×é¼þÖеĶÑÔ½½ç¶ÁÈ¡·ì϶£¬¸Ã·ì϶¿ÉÈÃδ¾­ÑéÖ¤µÄ¹¥»÷Õß·ÛËé²¢ÊÕÊÜMySQL Workbench¡£Oracle MySQL8.0.17¼°ÒÔǰ°æ±¾Êܵ½Ó°Ïì¡£


Oracle Enterprise Manager| CVE-2016-4000


CVE-2016-4000ÊÇOracle Enterprise ManagerÖеÄÒ»¸ö·ì϶£¬ËüÔÊÐíδ¾­ÑéÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâHTTPÒªÇóÒÔÆëÈ«ÊÕÊÜÒ×Êܹ¥»÷µÄÖ÷»ú¡£¸Ãȱµã´æÔÚÓÚOracleÆóÒµÖÎÀíÆ÷µÄJython×é¼þÖУ¬²¢ÔÊÐí¹¥»÷ÕßʹÓþ«ÐÄÔì×÷µÄÐòÁл¯PyType¶ÔÏóÖ´ÐÐËÁÒâ´úÂë¡£


Oracle Construction and Engineering| CVE-2017-6056,CVE-2019-14379,CVE-2019-14379ºÍCVE-2019-3020


CVE-2017-6056ÓëInstantis EnterpriseÓйØ£¬ÆäÓàCVEÊÇPrimaveraÖз¢Ïֵķì϶¡£¶ÔÓÚÕâЩCVEÖеÄÿһ¸ö£¬Î´¾­ÑéÖ¤µÄ¹¥»÷Õß¶¼Äܹ»ÏòÒ×Êܹ¥»÷µÄ×é¼þ·¢ËͶñÒâHTTPÒªÇ󣬲¢ÆëÈ«ÊÕÊÜÊܹ¥»÷µÄÖ¸±ê»ò¶ÔÆäÖ´ÐÐÖÎÀí²Ù×÷¡£ÊÜÓ°ÏìµÄPrimavera²úÆ·Ô̺¬Primavera P6¡¢Primavera GatewayºÍPrimavera Unifier¡£


Oracle Middleware| CVE-2016-1000031ºÍCVE-2019-2904


CVE-2016-1000031ÊÇÔÚApacheCommonsÎļþÉÏ´«¿âÖз¢ÏÖµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬Oracle CPU¶ÔËü²¢²»Ä°Éú¡£±¾Ô£¬¸Ã·ì϶ÔÚOracle FusionÖÐÑë¼þµÄÐ鹹Ŀ¼·þÎñÆ÷×é¼þÖеõ½½¨²¹¡£CVE×îÔçÊÇÓÉTenable ResearchÓÚ2016Äê·¢Ïֵ쬶ûºóÔÚ¶à¸öOracle²úÆ·ÖнøÐÐÁ˽¨²¹¡£´ËÒ×Êܹ¥»÷µÄ·ì϶ÔÊÐí¹¥»÷ÕßʹÓÃHTTPÒªÇó·çÏÕOracleÐ鹹Ŀ¼¡£


CVE-2019-2904ÊÇOracle JDeveloperµÄADF Faces×é¼þºÍOracle FusionÖÐÑë¼þµÄADF²úÆ·ÖеÄÒ»¸öδָ¶¨·ì϶¡£¸Ã·ì϶±»ÃèÊöΪ¡°Ò×ÓÚÀûÓá±£¬ÔÊÐíδ¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓþ«ÐļÙÔìµÄhttpÒªÇó·çÏÕ²¢ÊÕÊÜoracle jdeveloperºÍadf¡£


Oracle PeopleSoft| CVE-2016-0729,CVE-2019-3862


CVE-2016-0729ÊÇApacheXerces-CÖÐXML½âÎöÆ÷¿âÖеĶà¸ö¹Ø¼ü»º³åÇøÒç¶Âí½Å£¬×î³õÊÇÔÚ2016Ä꽨²¹µÄ¡£´Ë·ì϶´æÔÚÓÚoracleÖеɴúÀíÖС£Ëü¿ÉÄÜÔÊÐíδ¾­ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔì³É»Ø¾ø·þÎñ¡£


CVE-2019-3862ÊÇLISSH2ÖеÄÒ»¸öÔ½½ç¶ÁÈ¡·ì϶£¬Ô­ÒòÊÇÔÚSHSMSMSGCHANNELLÒªÇó°üÖÐûÓÐÕýÈ·µÄÍ˳ö״̬ÐÂÎŽâÎö¡£¸Ã·ì϶ÒÑÓÚ2019Äê3Ô½¨²¹¡£¸Ã·ì϶´æÔÚÓÚOracle PosioSoTµÄÎļþ´¦ÖÃÖ°ÄÜÖС£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html¡£


²Î¿¼Á´½Ó


https://www.oracle.com/technetwork/topics/security/public-vuln-to-advisory-mapping-093627.html

https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html