¡¾Îó²îͨ¸æ¡¿Oracle 7Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-07-21

0x00 Îó²î¸ÅÊö

2021Äê7ÔÂ20ÈÕ£¬£¬£¬£¬ £¬£¬OracleÐû²¼ÁË7Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼Æ342¸ö£¬£¬£¬£¬ £¬£¬Éæ¼°Oracle Communications Applications ¡¢Oracle E-Business Suite¡¢Oracle Enterprise ManagerºÍOracle Fusion MiddlewareµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£ ¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

Oracle Fusion Middleware¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË48¸öÊÊÓÃÓÚOracle Fusion MiddlewareµÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬ÆäÖÐÓÐ 35¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£ÆäÖаüÀ¨¶à¸öWebLogic ServerÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOP»òT3ЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬ £¬£¬´Ó¶øÔÚOracle WebLogic ServerÖ´ÐдúÂë»ò¿ØÖÆÐ§ÀÍÆ÷¡£ ¡£¡£¡£ÑÏÖØÎó²î°üÀ¨CVE-2021-2394¡¢CVE-2021-2397ºÍCVE-2021-2382£¬£¬£¬£¬ £¬£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8¡£ ¡£¡£¡£

 

Oracle Communications Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË33 ¸öÊÊÓÃÓÚ Oracle Communications Applications µÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬ÆäÖÐÓÐ 22 ¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2020-11612¡¢CVE-2021-3177¡¢CVE-2020-17530ºÍCVE-2019-17195£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£ ¡£¡£¡£

 

Oracle E-Business Suite¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË17 ¸öÊÊÓÃÓÚOracle E-Business Suite µÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬ÆäÖÐÓÐ3¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2021-2355£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬£¬ £¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬ £¬£¬ÇÒÎÞÐèÓû§½»»¥¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2021-2436¡¢CVE-2021-2359ºÍCVE-2021-2361ÔÚÄÚµÄ15¸ö¸ßΣÎó²î¡£ ¡£¡£¡£

 

Oracle Enterprise Manager¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË8 ¸öÊÊÓÃÓÚOracle Enterprise ManagerµÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬ÕâЩÎó²î¶¼¿ÉÒÔÔÚδ¾­ÓÉÉí·ÝÑéÖ¤µÄÇéÐÎÏÂÔ¶³ÌʹÓᣠ¡£¡£¡£ÆäÖÐÒ»¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îΪCVE-2020-10683£¨CVSSÆÀ·ÖΪ9.8£©£¬£¬£¬£¬ £¬£¬¸ÃÎó²îµÄʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬ £¬£¬ÇÒÎÞÐèÓû§½»»¥¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬Oracle»¹ÐÞ¸´Á˰üÀ¨CVE-2019-5064ÔÚÄ򵀮äËü7¸öÇå¾²Îó²î¡£ ¡£¡£¡£

 

Oracle Financial Services Applications¶à¸öÇå¾²Îó²î

Oracle´Ë´Î¹²Ðû²¼ÁË22¸öÊÊÓÃÓÚOracle Financial Services ApplicationsµÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬ÆäÖÐÓÐ 17¸öÎó²îÎÞÐè¾­ÓÉÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓᣠ¡£¡£¡£ÆäÖÐÑÏÖØÎó²î°üÀ¨CVE-2021-21345¡¢CVE-2019-0228¡¢CVE-2021-26117¡¢CVE-2020-5413¡¢CVE-2020-11998ºÍCVE-2020-27218£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýHTTPЭÒé·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î¡£ ¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚOracleÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬ £¬£¬½¨ÒéÓû§¾¡¿ìÐÞ¸´¡£ ¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/security-alerts/cpujul2021.html

 

»º½â²½·¥

½ûÓÃT3ЭÒ飺

1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬ £¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬ £¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬ £¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬ £¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣠ¡£¡£¡£

2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬ £¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬ £¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£ ¡£¡£¡£

3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬ £¬£¬¹æÔò·½¿ÉÉúЧ¡£ ¡£¡£¡£

image.png

 

½ûÓÃIIOPЭÒé:

Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬ £¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

image.png

 

0x03 ²Î¿¼Á´½Ó

https://www.oracle.com/security-alerts/cpujul2021.html

https://us-cert.cisa.gov/ncas/current-activity/2021/07/20/oracle-releases-july-2021-critical-patch-update

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2394

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-21

Ê×´ÎÐû²¼

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬ £¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png       image.png