Oracleȫϵ²úÆ·2019Äê10ÔÂÒªº¦²¹¶¡¸üÐÂÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-17

Îó²î¸ÅÊö


10ÔÂ15ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬OracleÐû²¼ÁË2019Äê10ÔµÄÒªº¦²¹¶¡¸üУ¨CPU£©£¬£¬ £¬£¬£¬£¬£¬£¬×÷Ϊ¼¾¶ÈÎó²îÐÞ¸´Ðû²¼µÄÒ»²¿·Ö¡£¡£¡£¡£¡£ ¡£´Ë¸üаüÀ¨¶à¸öOracle²úÆ·ÖÐ219¸ö²¹¶¡ÖÐ180¸öCVEµÄÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£ ¡£Éæ¼°Oracle Enterprise manager Products Suite¡¢Oracle Fusion Middleware¡¢Oracle Knowledge¡¢Oracle MySQLµÈ¶à¸ö²úÆ·¡£¡£¡£¡£¡£ ¡£


ÆäÖÐWeblogic Serve±£´æ¶à¸ö¸ßΣÎó²î


Oracle WebLogic Server| CVE-2019-2887, CVE-2019-2890, CVE-2019-2891


CVE-2019-2887ÓëCVE-2019-2890µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýT3ЭÒé¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³Ì¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬½ûÓÃT3ЭÒé²Ù×÷·½·¨¾ÙÐзÀ»¤¿É²Î¿¼Á´½Óhttps://mp.weixin.qq.com/s/YWTSyEVunQUordwxThrGwA¡£¡£¡£¡£¡£ ¡£


CVE-2019-2891¿Éµ¼Ö¹¥»÷ÕßÄÜ·¢ËÍHTTPÇëÇó¹¥»÷WebLogic Server¡£¡£¡£¡£¡£ ¡£


±ðµÄÉÐÓÐÒÔÏÂWebLogic ServerÎó²îÐèÒª¾ÙÐйØ×¢£ºCVE-2019-2888£¬£¬ £¬£¬£¬£¬£¬£¬CVE-2019-2889£¬£¬ £¬£¬£¬£¬£¬£¬CVE-2015-9251£¬£¬ £¬£¬£¬£¬£¬£¬CVE-2019-11358£¬£¬ £¬£¬£¬£¬£¬£¬CVE-2019-17091¡£¡£¡£¡£¡£ ¡£


±¾¼¾¶ÈµÄCPU»¹°üÀ¨18¸öCVSS 9+Îó²î£»£»£»£»£»£»£»Ê¹ÓÃÕâЩÎó²î¿ÉÄܵ¼ÖÂδÂÄÀúÖ¤µÄ»á¼û»òÍêÈ«½ÓÊÜÒ×Êܹ¥»÷µÄ×ʲú¡£¡£¡£¡£¡£ ¡£


CVE#

Product

BaseScore

CVE-2018-14721

Oracle NoSQL Database

10

CVE-2017-6056

Instantis EnterpriseTrack

9.8

CVE-2019-14379

Primavera Gateway

9.8

CVE-2019-14379

Primavera Unifier

9.8

CVE-2019-3020

Primavera P6 Enterprise Project Portfolio Management

9.3

CVE-2016-4000

Enterprise Manager Base Platform

9.8

CVE-2019-14379

Oracle Banking Platform

9.8

CVE-2019-14379

Oracle Financial Services Analytical Applications Infrastructure

9.8

CVE-2019-2904

Oracle JDeveloper and ADF

9.8

CVE-2016-1000031

Oracle Virtual Directory

9.8

CVE-2017-5645

JD Edwards EnterpriseOne Tools

9.8

CVE-2019-8457

MySQL Workbench

9.8

CVE-2016-0729

PeopleSoft Enterprise PeopleTools

9.8

CVE-2019-3862

PeopleSoft Enterprise PeopleTools

9.1

CVE-2018-19362

MICROS Retail XBRi Loss Prevention

9.8

CVE-2019-14379

Oracle Retail Xstore Point of Service

9.8

CVE-2018-1000007

Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers

9.8

CVE-2016-6814

Agile Recipe Management for Pharmaceuticals

9.8



ÕâÀïÎÒÃǸüÏêϸµØÐÎòÁËһЩCVSS 9+ÆÀ·ÖCVE£º


Oracle NoSQLÊý¾Ý¿â| CVE-2018-14721


±¾ÔÂ×îÖµµÃ×¢ÖØµÄ²¹¶¡Ö®Ò»½â¾öÁËCVE-2018-14721£¬£¬ £¬£¬£¬£¬£¬£¬ÕâÊÇOracle NoSQLÊý¾Ý¿âÖÐÓ°Ïì19.3.12֮ǰËùÓа汾µÄÎó²î¡£¡£¡£¡£¡£ ¡£¸ÃÎó²î±£´æÓÚJackson DATABONE NOSQL×é¼þÄÚ¡£¡£¡£¡£¡£ ¡£Í¨¹ýHTTP¾ÙÐÐÍøÂç»á¼ûµÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î½ÓÊÜOracle NoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£ ¡£´ËÎó²îÒÔǰÔÚÆäËûOracle²úÆ·£¨°üÀ¨Oracle 2019Äê1ÔµÄCPU£©ÖÐÒÑ»ñµÃ½â¾ö¡£¡£¡£¡£¡£ ¡£


Oracle MySQL| CVE-2019-8457


CVE-2019-8457ÊÇOracle MySQLµÄsqlite×é¼þÖеĶÑÔ½½ç¶ÁÈ¡Îó²î£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÈÃδÂÄÀúÖ¤µÄ¹¥»÷Õ߯ÆËð²¢½ÓÊÜMySQL Workbench¡£¡£¡£¡£¡£ ¡£Oracle MySQL8.0.17¼°ÒÔǰ°æ±¾Êܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£


Oracle Enterprise Manager| CVE-2016-4000


CVE-2016-4000ÊÇOracle Enterprise ManagerÖеÄÒ»¸öÎó²î£¬£¬ £¬£¬£¬£¬£¬£¬ËüÔÊÐíδÂÄÀúÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâHTTPÇëÇóÒÔÍêÈ«½ÓÊÜÒ×Êܹ¥»÷µÄÖ÷»ú¡£¡£¡£¡£¡£ ¡£¸ÃȱÏݱ£´æÓÚOracleÆóÒµÖÎÀíÆ÷µÄJython×é¼þÖУ¬£¬ £¬£¬£¬£¬£¬£¬²¢ÔÊÐí¹¥»÷ÕßʹÓÃÈ«ÐÄÖÆ×÷µÄÐòÁл¯PyType¹¤¾ßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£


Oracle Construction and Engineering| CVE-2017-6056,CVE-2019-14379,CVE-2019-14379ºÍCVE-2019-3020


CVE-2017-6056ÓëInstantis EnterpriseÓйØ£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÓàCVEÊÇPrimaveraÖз¢Ã÷µÄÎó²î¡£¡£¡£¡£¡£ ¡£¹ØÓÚÕâЩCVEÖеÄÿһ¸ö£¬£¬ £¬£¬£¬£¬£¬£¬Î´ÂÄÀúÖ¤µÄ¹¥»÷Õß¶¼¿ÉÒÔÏòÒ×Êܹ¥»÷µÄ×é¼þ·¢ËͶñÒâHTTPÇëÇ󣬣¬ £¬£¬£¬£¬£¬£¬²¢ÍêÈ«½ÓÊÜÊܹ¥»÷µÄÄ¿µÄ»ò¶ÔÆäÖ´ÐÐÖÎÀí²Ù×÷¡£¡£¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄPrimavera²úÆ·°üÀ¨Primavera P6¡¢Primavera GatewayºÍPrimavera Unifier¡£¡£¡£¡£¡£ ¡£


Oracle Middleware| CVE-2016-1000031ºÍCVE-2019-2904


CVE-2016-1000031ÊÇÔÚApacheCommonsÎļþÉÏ´«¿âÖз¢Ã÷µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬£¬£¬Oracle CPU¶ÔËü²¢²»ÉúÊè¡£¡£¡£¡£¡£ ¡£±¾Ô£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÚOracle FusionÖÐÐļþµÄÐéÄâĿ¼ЧÀÍÆ÷×é¼þÖлñµÃÐÞ²¹¡£¡£¡£¡£¡£ ¡£CVE×îÔçÊÇÓÉTenable ResearchÓÚ2016Äê·¢Ã÷µÄ£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔºóÔÚ¶à¸öOracle²úÆ·ÖоÙÐÐÁËÐÞ²¹¡£¡£¡£¡£¡£ ¡£´ËÒ×Êܹ¥»÷µÄÎó²îÔÊÐí¹¥»÷ÕßʹÓÃHTTPÇëÇóΣº¦OracleÐéÄâĿ¼¡£¡£¡£¡£¡£ ¡£


CVE-2019-2904ÊÇOracle JDeveloperµÄADF Faces×é¼þºÍOracle FusionÖÐÐļþµÄADF²úÆ·ÖеÄÒ»¸öδָ¶¨Îó²î¡£¡£¡£¡£¡£ ¡£¸ÃÎó²î±»ÐÎòΪ¡°Ò×ÓÚʹÓá±£¬£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíδÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃÈ«ÐÄÌåÀýµÄhttpÇëÇóΣº¦²¢½ÓÊÜoracle jdeveloperºÍadf¡£¡£¡£¡£¡£ ¡£


Oracle PeopleSoft| CVE-2016-0729,CVE-2019-3862


CVE-2016-0729ÊÇApacheXerces-CÖÐXMLÆÊÎöÆ÷¿âÖеĶà¸öÒªº¦»º³åÇøÒç³öÎó²î£¬£¬ £¬£¬£¬£¬£¬£¬×î³õÊÇÔÚ2016ÄêÐÞ²¹µÄ¡£¡£¡£¡£¡£ ¡£´ËÎó²î±£´æÓÚoracleÖеÉÊðÀíÖС£¡£¡£¡£¡£ ¡£Ëü¿ÉÄÜÔÊÐíδÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔì³É¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£ ¡£


CVE-2019-3862ÊÇLISSH2ÖеÄÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬£¬ £¬£¬£¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÊÇÔÚSHSMSMSGCHANNELLÇëÇó°üÖÐûÓÐ׼ȷµÄÍ˳ö״̬ÐÂÎÅÆÊÎö¡£¡£¡£¡£¡£ ¡£¸ÃÎó²îÒÑÓÚ2019Äê3ÔÂÐÞ²¹¡£¡£¡£¡£¡£ ¡£¸ÃÎó²î±£´æÓÚOracle PosioSoTµÄÎļþ´¦Öóͷ£¹¦Ð§ÖС£¡£¡£¡£¡£ ¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬ £¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html¡£¡£¡£¡£¡£ ¡£


²Î¿¼Á´½Ó


https://www.oracle.com/technetwork/topics/security/public-vuln-to-advisory-mapping-093627.html

https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html