Oracle | 10Ô¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-10-210x00 ·ì϶¸ÅÊö
2020Äê10ÔÂ20ÈÕ£¬Oracle°ä²¼10Ô·ݵݲȫ¸üУ¬½¨¸´Á˶à¸ö²úÆ·Öеݲȫ·ì϶¡£Õâ´Î°ä²¼µÄ·ì϶²¹¶¡¹²¼Æ402¸ö£¬ÖØÒªÉæ¼°Oracle Database Server¡¢Oracle Communications¡¢Oracle Fusion Middleware¡¢Oracle Weblogic¡¢Oracle E-Business SuiteºÍOracle MySQLµÈ²úÆ·£¬ÆäÖжà¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ¡£
0x01 ·ì϶ÏêÇé

Oracle Database Server
Õâ´Î¸üÐÂÖÐÔ̺¬OracleÊý¾Ý¿âµÄ18¸öµÄ°²È«²¹¶¡¡£ÆäÖÐÓÐ4¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º
·ì϶±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°ÏìÁìÓò |
CVE-2020-13935 | Workload Manager (Apache Tomcat) | None | 7.5 | 12.2.0.1, 18c, 19c |
CVE-2020-14734 | Oracle Text | None | 8.1 | 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c |
CVE-2020-14735 | Scheduler | Local Logon | 8.8 | 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c |
Oracle Communications¼° Oracle Communications Applications
Õâ´Î¸üÐÂÖÐÔ̺¬Oracle CommunicationsµÄ52¸öµÄ°²È«²¹¶¡ºÍ9¸öOracle Communications Applications°²È«²¹¶¡£¬ÆäÖÐÓÐ41¸öOracle Communications·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º
·ì϶±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°ÏìÁìÓò |
CVE-2020-2555 | Oracle WebCenter Portal | Database Module (Oracle Coherence) | 9.8 | 12.2.1.3.0£¬ 12.2.1.4.0 |
CVE-2020-10683 | Oracle Communications Unified Inventory Management | Core (dom4j) | 9.8 | 7.3.0£¬7.4.0 |
CVE-2020-10878 | Oracle Communications Billing and Revenue Management | Core (Perl) | 8.6 | 12.0.0.2.0£¬ 12.0.0.3.0 |
CVE-2020-11973 | Oracle Communications Diameter Signaling Router (DSR) | IDIH (Apache Camel) | 9.8 | IDIH: 8.0.0-8.2.2 |
CVE-2020-11984 | Oracle Communications Element Manager | Core (Apache HTTP Server) | 9.8 | 8.2.0-8.2.2 |
Oracle Fusion Middleware
Õâ´Î¸üÐÂÖÐÔ̺¬Oracle Fusion MiddlewareµÄ46¸ö°²È«²¹¶¡¡£ÆäÖÐÓÐ36¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆäÖÐÉæ¼°Á˶à¸öWeblogic·´ÐòÁл¯·ì϶£¬ÕâЩ·ì϶ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýHTTP¡¢IIOP¡¢T3ºÍ̸·¢ËͶñÒâÒªÇ󣬴ӶøÔÚOracle WebLogic ServerÖ´ÐдúÂë¡£²¿ÃÅÑϳÁ·ì϶ÈçÏ£º
·ì϶±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°ÏìÁìÓò |
CVE-2020-14820 | Oracle WebLogic Server | Core | 7.5 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14825 | Oracle WebLogic Server | Core | 9.8 | 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14841 | Oracle WebLogic Server | Core | 9.8 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14859 | Oracle WebLogic Server | Core | 9.8 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
CVE-2020-14882 | Oracle WebLogic Server | Console | 9.8 | 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 |
Oracle E-Business Suite
Õâ´Î¸üÐÂÔ̺¬Oracle E-Business SuiteµÄ27¸ö°²È«²¹¶¡¡£ÆäÖеÄ25¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º
·ì϶±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°ÏìÁìÓò |
CVE-2020-14805 | Oracle E-Business Suite Secure Enterprise Search | Search Integration Engine | 9.1 | 12.1.3, 12.2.3 - 12.2.10 |
CVE-2020-14855 | Oracle Universal Work Queue | Work Provider Administration | 9.8 | 12.1.3 |
CVE-2020-14862 | Oracle Universal Work Queue | Internal Operations | 8.8 | 12.2.3 - 12.2.9 |
CVE-2020-14875 | Oracle Marketing | Marketing Administration | 9.1 | 12.1.1 - 12.1.3, 12.2.3 - 12.2.10 |
CVE-2020-14876 | Oracle Trade Management | User Interface | 9.1 | 12.1.1 - 12.1.3, 12.2.3 - 12.2.10 |
Oracle MySQL
Õâ´Î¸üÐÂÖÐÔ̺¬Oracle MysqlµÄ54¸öµÄ°²È«²¹¶¡¡£ÆäÖÐÓÐ4¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣲ¿ÃÅÑϳÁ·ì϶ÈçÏ£º
·ì϶±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°ÏìÁìÓò |
CVE-2020-8174 | MySQL Cluster | Cluster: JS module (Node.js) | 9.8 | 7.3.30 and prior, 7.4.29 and prior, 7.5.19 and prior, 7.6.15 and prior, 8.0.21 and prior |
CVE-2020-13935 | MySQL Enterprise Monitor | Monitoring: General (Apache Tomcat) | 7.5 | 8.0.21 and prior |
CVE-2020-14878 | MySQL Server | Server: Security: LDAP Auth | 8.0 | 8.0.21 and prior |
´Ë±í£¬ÔÚ±¾´Î°ä²¼µÄ¶à¸ö°²È«·ì϶Öл¹Ô̺¬2¸öÆÀ·ÖΪ10£¨Âú·Ö10·Ö£©µÄ·ì϶£¬ÈçÏ£º
·ì϶±àºÅ | ²úÆ· | ×é¼þ | ÆÀ·Ö | Ó°ÏìÁìÓò |
CVE-2020-1953 | Oracle Healthcare Foundation | Self Service Analytics (Apache Commons Configuration) | 10.0 | 7.1.1£¬7.2.0£¬7.2.1£¬7.3.0 |
CVE-2020-14871 | Oracle Solaris | Pluggable authentication module | 10.0 | 10£¬11 |
Oracle Healthcare Foundation Self Service Analytics·ì϶£¨CVE-2020-1953£©
¸Ã·ì϶ÊÇÓÉÓÚOracle Healthcare FoundationµÄ×ÔÖ÷·ÖÎö·þÎñ£¨Apache Commons Configuration£©Ê¹ÓõÚÈý·½¿âÀ´½âÎöYAMLÎļþ£¬ÈôÊÇYAMLÔ̺¬ÌØÊâÓï¾ä£¬ÔòĬÈÏÇé¿öÏÂËüÔÊÐíÊ·ý»¯Àà¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓÕµ¼Óû§´Ó²»ÊÜÐÅÀµµÄÔ´¼ÓÔØYAMLÎļþÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚÖ÷»úÀûÓ÷¨Ê½µÄ½ÚÔìÁìÓòÖ®±í¼ÓÔØ²¢Ö´ÐдúÂë¡£
Ó°ÏìÁìÓò£º
Apache Commons Configuration2.2£¬2.3£¬2.4£¬2.5£¬2.6
Oracle Healthcare Foundation 7.1.1£¬7.2.0£¬7.2.1£¬7.3.0
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1953
Oracle Solaris Pluggable authentication module·ì϶(CVE-2020-14871)
¸Ã·ì϶µÄϸ½ÚÁÙʱδ¹«¿ª¡£
Ó°ÏìÁìÓò£º
Oracle Solaris10£¬11
²Î¿¼Á´½Ó£º
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14871
0x02 ´ëÖý¨Òé
½¨Òé²Î¿¼¹Ù·½°ä²¼µÄ²¹¶¡¸üÐÂÐÅϢʵʱ½¨¸´»òÉý¼¶ÖÁ°²È«°æ±¾¡£
Á´½ÓµØÖ·£º
https://www.oracle.com/security-alerts/cpuoct2020.html
ÏÂÔØµØÖ·£º
https://www.oracle.com/cn/downloads/
ÆäËü´ëÊ©£º
ÈôÊDz»ÒÀÀµT3ºÍ̸ºÍIIOPºÍ̸½øÐÐJVMͨѶ£¬Ôò½¨Òé½ûÓá£
0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/
https://us-cert.cisa.gov/ncas/current-activity/2020/10/20/oracle-releases-october-2020-security-bulletin-0
0x04 ¹¦·òÏß
2020-10-20 Oracle°ä²¼°²È«¸üÐÂ
2020-10-21 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ