Oracleȫϵ²úÆ·2019Äê10ÔÂÒªº¦²¹¶¡¸üÐÂÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-17Îó²î¸ÅÊö
10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬OracleÐû²¼ÁË2019Äê10ÔµÄÒªº¦²¹¶¡¸üУ¨CPU£©£¬£¬£¬£¬£¬£¬×÷Ϊ¼¾¶ÈÎó²îÐÞ¸´Ðû²¼µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£´Ë¸üаüÀ¨¶à¸öOracle²úÆ·ÖÐ219¸ö²¹¶¡ÖÐ180¸öCVEµÄÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£Éæ¼°Oracle Enterprise manager Products Suite¡¢Oracle Fusion Middleware¡¢Oracle Knowledge¡¢Oracle MySQLµÈ¶à¸ö²úÆ·¡£¡£¡£¡£¡£¡£
ÆäÖÐWeblogic Serve±£´æ¶à¸ö¸ßΣÎó²î
Oracle WebLogic Server| CVE-2019-2887, CVE-2019-2890, CVE-2019-2891
CVE-2019-2887ÓëCVE-2019-2890µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýT3ÐÒé¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³Ì¹¥»÷£¬£¬£¬£¬£¬£¬½ûÓÃT3ÐÒé²Ù×÷·½·¨¾ÙÐзÀ»¤¿É²Î¿¼Á´½Óhttps://mp.weixin.qq.com/s/YWTSyEVunQUordwxThrGwA¡£¡£¡£¡£¡£¡£
CVE-2019-2891¿Éµ¼Ö¹¥»÷ÕßÄÜ·¢ËÍHTTPÇëÇó¹¥»÷WebLogic Server¡£¡£¡£¡£¡£¡£
±ðµÄÉÐÓÐÒÔÏÂWebLogic ServerÎó²îÐèÒª¾ÙÐйØ×¢£ºCVE-2019-2888£¬£¬£¬£¬£¬£¬CVE-2019-2889£¬£¬£¬£¬£¬£¬CVE-2015-9251£¬£¬£¬£¬£¬£¬CVE-2019-11358£¬£¬£¬£¬£¬£¬CVE-2019-17091¡£¡£¡£¡£¡£¡£
±¾¼¾¶ÈµÄCPU»¹°üÀ¨18¸öCVSS 9+Îó²î£»£»£»£»Ê¹ÓÃÕâЩÎó²î¿ÉÄܵ¼ÖÂδÂÄÀúÖ¤µÄ»á¼û»òÍêÈ«½ÓÊÜÒ×Êܹ¥»÷µÄ×ʲú¡£¡£¡£¡£¡£¡£
CVE# |
Product |
BaseScore |
CVE-2018-14721 |
Oracle NoSQL Database |
10 |
CVE-2017-6056 |
Instantis EnterpriseTrack |
9.8 |
CVE-2019-14379 |
Primavera Gateway |
9.8 |
CVE-2019-14379 |
Primavera Unifier |
9.8 |
CVE-2019-3020 |
Primavera P6 Enterprise Project Portfolio Management |
9.3 |
CVE-2016-4000 |
Enterprise Manager Base Platform |
9.8 |
CVE-2019-14379 |
Oracle Banking Platform |
9.8 |
CVE-2019-14379 |
Oracle Financial Services Analytical Applications Infrastructure |
9.8 |
CVE-2019-2904 |
Oracle JDeveloper and ADF |
9.8 |
CVE-2016-1000031 |
Oracle Virtual Directory |
9.8 |
CVE-2017-5645 |
JD Edwards EnterpriseOne Tools |
9.8 |
CVE-2019-8457 |
MySQL Workbench |
9.8 |
CVE-2016-0729 |
PeopleSoft Enterprise PeopleTools |
9.8 |
CVE-2019-3862 |
PeopleSoft Enterprise PeopleTools |
9.1 |
CVE-2018-19362 |
MICROS Retail XBRi Loss Prevention |
9.8 |
CVE-2019-14379 |
Oracle Retail Xstore Point of Service |
9.8 |
CVE-2018-1000007 |
Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers |
9.8 |
CVE-2016-6814 |
Agile Recipe Management for Pharmaceuticals |
9.8 |
ÕâÀïÎÒÃǸüÏêϸµØÐÎòÁËһЩCVSS 9+ÆÀ·ÖCVE£º
Oracle NoSQLÊý¾Ý¿â| CVE-2018-14721
±¾ÔÂ×îÖµµÃ×¢ÖØµÄ²¹¶¡Ö®Ò»½â¾öÁËCVE-2018-14721£¬£¬£¬£¬£¬£¬ÕâÊÇOracle NoSQLÊý¾Ý¿âÖÐÓ°Ïì19.3.12֮ǰËùÓа汾µÄÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚJackson DATABONE NOSQL×é¼þÄÚ¡£¡£¡£¡£¡£¡£Í¨¹ýHTTP¾ÙÐÐÍøÂç»á¼ûµÄδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î½ÓÊÜOracle NoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£¡£´ËÎó²îÒÔǰÔÚÆäËûOracle²úÆ·£¨°üÀ¨Oracle 2019Äê1ÔµÄCPU£©ÖÐÒÑ»ñµÃ½â¾ö¡£¡£¡£¡£¡£¡£
Oracle MySQL| CVE-2019-8457
CVE-2019-8457ÊÇOracle MySQLµÄsqlite×é¼þÖеĶÑÔ½½ç¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÈÃδÂÄÀúÖ¤µÄ¹¥»÷Õ߯ÆËð²¢½ÓÊÜMySQL Workbench¡£¡£¡£¡£¡£¡£Oracle MySQL8.0.17¼°ÒÔǰ°æ±¾Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
Oracle Enterprise Manager| CVE-2016-4000
CVE-2016-4000ÊÇOracle Enterprise ManagerÖеÄÒ»¸öÎó²î£¬£¬£¬£¬£¬£¬ËüÔÊÐíδÂÄÀúÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâHTTPÇëÇóÒÔÍêÈ«½ÓÊÜÒ×Êܹ¥»÷µÄÖ÷»ú¡£¡£¡£¡£¡£¡£¸ÃȱÏݱ£´æÓÚOracleÆóÒµÖÎÀíÆ÷µÄJython×é¼þÖУ¬£¬£¬£¬£¬£¬²¢ÔÊÐí¹¥»÷ÕßʹÓÃÈ«ÐÄÖÆ×÷µÄÐòÁл¯PyType¹¤¾ßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
Oracle Construction and Engineering| CVE-2017-6056,CVE-2019-14379,CVE-2019-14379ºÍCVE-2019-3020
CVE-2017-6056ÓëInstantis EnterpriseÓйأ¬£¬£¬£¬£¬£¬ÆäÓàCVEÊÇPrimaveraÖз¢Ã÷µÄÎó²î¡£¡£¡£¡£¡£¡£¹ØÓÚÕâЩCVEÖеÄÿһ¸ö£¬£¬£¬£¬£¬£¬Î´ÂÄÀúÖ¤µÄ¹¥»÷Õß¶¼¿ÉÒÔÏòÒ×Êܹ¥»÷µÄ×é¼þ·¢ËͶñÒâHTTPÇëÇ󣬣¬£¬£¬£¬£¬²¢ÍêÈ«½ÓÊÜÊܹ¥»÷µÄÄ¿µÄ»ò¶ÔÆäÖ´ÐÐÖÎÀí²Ù×÷¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄPrimavera²úÆ·°üÀ¨Primavera P6¡¢Primavera GatewayºÍPrimavera Unifier¡£¡£¡£¡£¡£¡£
Oracle Middleware| CVE-2016-1000031ºÍCVE-2019-2904
CVE-2016-1000031ÊÇÔÚApacheCommonsÎļþÉÏ´«¿âÖз¢Ã÷µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬Oracle CPU¶ÔËü²¢²»ÉúÊè¡£¡£¡£¡£¡£¡£±¾Ô£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÚOracle FusionÖÐÐļþµÄÐéÄâĿ¼ЧÀÍÆ÷×é¼þÖлñµÃÐÞ²¹¡£¡£¡£¡£¡£¡£CVE×îÔçÊÇÓÉTenable ResearchÓÚ2016Äê·¢Ã÷µÄ£¬£¬£¬£¬£¬£¬ÒÔºóÔÚ¶à¸öOracle²úÆ·ÖоÙÐÐÁËÐÞ²¹¡£¡£¡£¡£¡£¡£´ËÒ×Êܹ¥»÷µÄÎó²îÔÊÐí¹¥»÷ÕßʹÓÃHTTPÇëÇóΣº¦OracleÐéÄâĿ¼¡£¡£¡£¡£¡£¡£
CVE-2019-2904ÊÇOracle JDeveloperµÄADF Faces×é¼þºÍOracle FusionÖÐÐļþµÄADF²úÆ·ÖеÄÒ»¸öδָ¶¨Îó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»ÐÎòΪ¡°Ò×ÓÚʹÓá±£¬£¬£¬£¬£¬£¬ÔÊÐíδÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃÈ«ÐÄÌåÀýµÄhttpÇëÇóΣº¦²¢½ÓÊÜoracle jdeveloperºÍadf¡£¡£¡£¡£¡£¡£
Oracle PeopleSoft| CVE-2016-0729,CVE-2019-3862
CVE-2016-0729ÊÇApacheXerces-CÖÐXMLÆÊÎöÆ÷¿âÖеĶà¸öÒªº¦»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬×î³õÊÇÔÚ2016ÄêÐÞ²¹µÄ¡£¡£¡£¡£¡£¡£´ËÎó²î±£´æÓÚoracleÖеÉÊðÀíÖС£¡£¡£¡£¡£¡£Ëü¿ÉÄÜÔÊÐíδÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔì³É¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£
CVE-2019-3862ÊÇLISSH2ÖеÄÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔÓÉÊÇÔÚSHSMSMSGCHANNELLÇëÇó°üÖÐûÓÐ׼ȷµÄÍ˳ö״̬ÐÂÎÅÆÊÎö¡£¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÓÚ2019Äê3ÔÂÐÞ²¹¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚOracle PosioSoTµÄÎļþ´¦Öóͷ£¹¦Ð§ÖС£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.oracle.com/technetwork/topics/security/public-vuln-to-advisory-mapping-093627.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html