¡¾·ì϶¹«¸æ¡¿Oracle 10Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-10-20

0x00 ·ì϶¸ÅÊö

2021Äê10ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Oracle°ä²¼ÁË10Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬£¬£¬£¬±¾´Î°ä²¼µÄ°²È«¸üй²¼Æ419¸ö£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Financial Services Applications¡¢Oracle Enterprise Manager¡¢Oracle Fusion Middleware¡¢Oracle Java SE¡¢Oracle MySQLºÍOracle SystemsµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£ ¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

image.png

l  Oracle Fusion Middleware¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË38¸öºÏÓÃÓÚOracle Fusion MiddlewareµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ 30¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£±¾´Î°ä²¼µÄ¸üÐÂÉæ¼°¶à¸öOracle WebLogic Server·ì϶£ºCVE-2021-35617¡¢CVE-2021-35620ºÍCVE-2021-35552µÈ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2021-35617µÄCVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷¸´ÔӶȵÍ£¬£¬£¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýIIOPºÍ̸¶ÔOracle WebLogic ServerÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»½ÚÔìOracle WebLogic Server¡£¡£¡£¡£¡£ ¡£¡£¡£


l  Oracle Communications Applications¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË19¸öºÏÓÃÓÚ Oracle Communications Applications µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ14¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£ÆäÖÐÑϳÁ·ì϶Ô̺¬CVE-2021-3177£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£ ¡£¡£¡£

 

l  Oracle E-Business Suite¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË18¸öºÏÓÃÓÚOracle E-Business Suite µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ4¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£ÆäÖÐÔ̺¬CVE-2021-35566¡¢CVE-2021-2483¡¢CVE-2021-35536ºÍCVE-2021-35585µÈ11¸ö¸ßΣ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ8.1¡£¡£¡£¡£¡£ ¡£¡£¡£

 

l  Oracle Enterprise Manager¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË8¸öºÏÓÃÓÚOracle Enterprise ManagerµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ5¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶ΪCVE-2021-26691£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄÀûÓø´ÔӶȵÍ£¬£¬£¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Oracle»¹½¨¸´ÁËÔ̺¬CVE-2021-2137ºÍCVE-2021-29505ÔÚÄ򵀮äËü7¸ö°²È«·ì϶¡£¡£¡£¡£¡£ ¡£¡£¡£

 

l  Oracle Financial Services Applications¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË44¸öºÏÓÃÓÚOracle Financial Services ApplicationsµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ26¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£ÆäÖÐÑϳÁ·ì϶Ô̺¬CVE-2021-21345¡¢CVE-2020-5413ºÍCVE-2020-10683£¬£¬£¬£¬£¬£¬£¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£¡£¡£¡£¡£ ¡£¡£¡£

 

l  Oracle Java SE¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË15¸öºÏÓÃÓÚOracle Java SEµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ13¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£ÆäÖиßΣ·ì϶Ô̺¬CVE-2021-3517¡¢CVE-2021-35560ºÍCVE-2021-27290¡£¡£¡£¡£¡£ ¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬CVE-2021-3517ºÍCVE-2021-35560Ó°ÏìÁËJava SE 8u301¡£¡£¡£¡£¡£ ¡£¡£¡£

 

l  Oracle MySQL¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË66¸öºÏÓÃÓÚOracle MySQLµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ10¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£ÑϳÁ·ì϶Ô̺¬CVE-2021-22931£¨Ó°ÏìMySQL¼¯Èº£©ºÍCVE-2021-3711£¨Ó°ÏìMySQL ·þÎñÆ÷£©£¬£¬£¬£¬£¬£¬£¬£¬Õâ2¸ö·ì϶µÄCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷¸´ÔӶȵÍ£¬£¬£¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£ ¡£¡£¡£

 

l  Oracle Systems¶à¸ö°²È«·ì϶

OracleÕâ´Î¹²°ä²¼ÁË5¸öºÏÓÃÓÚOracle SystemsµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ2¸ö·ì϶ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£¡£¡£ÑϳÁ·ì϶Ô̺¬CVE-2021-26691£¬£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷¸´ÔӶȵÍ£¬£¬£¬£¬£¬£¬£¬£¬ÇÒÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Oracle»¹°ä²¼ÁËCVE-2021-35539¡¢CVE-2021-35589¡¢CVE-2021-35549ºÍCVE-2020-1968µÈ¶à¸ö·ì϶µÄ²¹¶¡¡£¡£¡£¡£¡£ ¡£¡£¡£

 

0x02 ´ëÖý¨Òé

ĿǰOracleÒѾ­°ä²¼ÁËÓйز¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üС£¡£¡£¡£¡£ ¡£¡£¡£

·ì϶ÁÐ±í¼°Ó°ÏìÁìÓòÇë²Î¿¼Oracle¹Ù·½²¼¸æ£º

https://www.oracle.com/security-alerts/cpuoct2021.html

 

»º½â´ëÊ©

Õë¶ÔWebLogic£¬£¬£¬£¬£¬£¬£¬£¬½¨Òé½ûÓÃT3ºÍ̸»òIIOPºÍ̸¡£¡£¡£¡£¡£ ¡£¡£¡£

½ûÓÃT3ºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬¾ßÌå²Ù×÷£º

1£©½øÈëWebLogic½ÚÔį̀£¬£¬£¬£¬£¬£¬£¬£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬£¬£¬£¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬£¬£¬£¬½øÈëÏνÓɸѡÆ÷ÅäÖᣡ£¡£¡£¡£ ¡£¡£¡£

2)ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û)¡£¡£¡£¡£¡£ ¡£¡£¡£

3£©±£ÁôºóÐè³ÁÐÂÆô¶¯£¬£¬£¬£¬£¬£¬£¬£¬¹æ¶¨·½¿ÉÉúЧ¡£¡£¡£¡£¡£ ¡£¡£¡£

image.png

 

½ûÓÃIIOPºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬¾ßÌå²Ù×÷£º

µÇ½WebLogic½ÚÔį̀£¬£¬£¬£¬£¬£¬£¬£¬base_domain >·þÎñÆ÷¸ÅÒª >AdminServer

image.png

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpuoct2021.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22931

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-10-20

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png