Oracle 4Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-04-210x00 ·ì϶¸ÅÊö
2021Äê04ÔÂ20ÈÕ£¬Oracle°ä²¼ÁË4Ô·ݵݲȫ¸üУ¬±¾´Î°ä²¼µÄ°²È«²¹¶¡¹²¼Æ390¸ö£¬Éæ¼°Oracle Fusion Middleware¡¢Oracle E-Business Suite¡¢Oracle Communications ApplicationsºÍOracle MySQLµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£
0x01 ·ì϶ÏêÇé

ÔÚ±¾´Î°ä²¼µÄ°²È«²¹¶¡ÖУ¬Oracle Fusion MiddlewareÓйصIJ¹¶¡Îª45¸ö£¬ÆäÖÐ36¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£Weblogic Server²¿ÃÅ·ì϶ÏêÇéÈçÏ£º
Oracle WebLogic Server Coherence Container°²È«·ì϶£¨CVE-2021-2135£©
δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýT3»òIIOPºÍ̸·¢ËͶñÒâÒªÇó£¬×îÖÕ½ÚÔì·þÎñÆ÷¡£¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÆäCVSSÆÀ·ÖΪ9.8¡£
Ó°ÏìÁìÓò
12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0
Oracle WebLogic Server Core°²È«·ì϶£¨CVE-2021-2136£©
δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýIIOPºÍ̸·¢ËͶñÒâÒªÇó£¬×îÖÕ½ÚÔì·þÎñÆ÷¡£¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÆäCVSSÆÀ·ÖΪ9.8¡£
Ó°ÏìÁìÓò
12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0
Oracle WebLogic Server TopLink Integration°²È«·ì϶£¨CVE-2021-2157£©
δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýHTTP·¢ËͶñÒâÒªÇó£¬×îÖÕÄܹ»Î´ÊÚȨ½Ó¼û¹Ø¼üÊý¾Ý¡£¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÆäCVSSÆÀ·ÖΪ7.5¡£
Ó°ÏìÁìÓò
10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0
´Ë±í£¬ÔÚOracle±¾´Î°ä²¼µÄ°²È«²¹¶¡ÖУº
ÓëOracle Communications ApplicationsÓйصIJ¹¶¡Îª13¸ö£¬ÆäÖÐCVE-2020-11612ºÍCVE-2020-28052ÆÀ·ÖΪ9.8£¬¹¥»÷ÕßÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓÃÔ̺¬Õâ2¸ö·ì϶ÔÚÄÚµÄ12¸ö°²È«·ì϶¡£
ÓëE-Business SuiteÓйصIJ¹¶¡Îª70¸ö£¬ÆäÖÐCVE-2021-2200ºÍCVE-2021-2205ÆÀ·ÖΪ9.1£¬¹¥»÷ÕßÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓÃÔ̺¬Õâ2¸ö·ì϶ÔÚÄÚµÄ22¸ö°²È«·ì϶¡£
ÓëOracle MySQLÓйصIJ¹¶¡Îª49¸ö£¬ÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿ÉÀûÓõķì϶Ϊ10¸ö£¬ÆäÖÐCVE-2021-3449ºÍCVE-2021-3450£¨¾ùΪMySQL ServerÖеÄOpenSSLÎÊÌ⣩ÆÀ·Ö±ðÀëΪ7.5ºÍ7.4, CVE-2021-2307ΪMySQL for WindowsÖеÄȨÏÞÌáÉý·ì϶£¬¸Ã·ì϶Ðè¾¹ýÑéÖ¤ÄÜÁ¦ÀûÓã¬ÆäCVSSÆÀ·ÖΪ6.1¡£
0x02 ´ëÖý¨Òé
ĿǰOracleÒѾ°ä²¼Óйذ²È«²¹¶¡£¬½¨Ò龡¿ìÀûÓá£
ÏÂÔØÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2021.html
0x03 ²Î¿¼Á´½Ó
https://www.oracle.com/security-alerts/cpuapr2021.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2135
https://kb.cert.org/vuls/id/567764
0x04 ¹¦·òÏß
2021-04-20 Oracle°ä²¼°²È«¸üÐÂ
2021-04-21 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ