【安全通告】Oracle全系产品2020年10月关键补丁

一、概述

2020年10月21日,绿盟科技监测到Oracle官方发布了2020年10月关键补丁更新公告(Critical Patch Update),此次更新修复了402个不同程度的漏洞,其中271个漏洞可被远程未经身份认证的攻击者利用。此次更新涉及Oracle Database Server、Oracle Weblogic Server、Oracle Java SE、Oracle MySQL等多个产品。各产品受影响情况及可用补丁请见附录。Oracle强烈建议客户尽快应用关键补丁更新修复程序,对漏洞进行修复。

参考链接:

https://www.oracle.com/security-alerts/cpuoct2020.html

二、修复漏洞总结

此次关键补丁更新(CPU)修复的漏洞中CVSS评分为9.8及以上的漏洞有247个,涉及Oracle Weblogic Server、Oracle MySQL、Oracle Systems、Oracle Fusion Middleware等多个产品。

其中Weblogic Serve存在多个高危漏洞,WebLogic IIOP JNDI 注入漏洞(CVE-2020-14841),(CVE-2020-14825) 与(CVE-2020-14859)导致攻击者可以在未授权的情况下通过IIOP/T3协议对存在漏洞的WebLogic组件进行远程攻击,通过禁用IIOP/T3协议进行防护可参考文章的4.2节https://mp.weixin.qq.com/s/ruQdLU4Rn3S62bRt7oz7oQ;(CVE-2019-17267)与(CVE-2020-14882)可导致攻击者能发送HTTP请求攻击WebLogic Server;此外还有以下WebLogic Server漏洞需要进行关注:(CVE-2020-14820、CVE-2020-14883、CVE-2020-14757、CVE-2020-11022)。

Oracle官方10月关键补丁更新漏洞总结如下:

产品漏洞个数未授权远程利用个数最高CVSS评分
Oracle Database server2838.8
Oracle Big Data Graph519.8
Oracle REST Data Services729.8
Oracle TimesTen In-Memory Database449.8
Oracle Communications Applications989.8
Oracle Communications52419.8
Oracle Construction and Engineering979.8
Oracle E-Business Suite27259.8
Oracle Enterprise Manager11109.8
Oracle Financial Services Applications52489.8
Oracle Food and Beverage Applications436.1
Oracle Fusion Middleware46369.8
Oracle GraalVM115.3
Oracle Health Sciences4410.0
Oracle Hospitality Applications639.4
Oracle Hyperion919.8
Oracle Insurance Applications669.8
Oracle Java SE885.3
Oracle MySQL5449.8
Oracle PeopleSoft15129.8
Oracle Policy Automation666.1
Oracle Retail Applications28259.8
Oracle Siebel CRM339.8
Oracle Supply Chain439.8
Oracle Systems10410.0
Oracle Utilities Applications539.8
Oracle Virtualization708.2

三、漏洞防护

请用户参考本文附录“受影响产品及补丁信息”及时下载受影响产品更新补丁,并参照补丁安装包中的readme文件进行安装更新,以保证长期有效的防护。

注:Oracle官方补丁需要用户持有正版软件的许可账号,使用该账号登陆https://support.oracle.com后,可以下载最新补丁。

附录:受影响产品及补丁信息

受影响产品及版本号可用补丁
Application Performance Management (APM), versions 13.3.0.0, 13.4.0.0https://support.oracle.com/rs?type=doc&id=2694898.1
Big Data Spatial and Graph, versions prior to 3.0https://support.oracle.com/rs?type=doc&id=2694898.1
Enterprise Manager Base Platform, versions 13.2.1.0, 13.3.0.0, 13.4.0.0https://support.oracle.com/rs?type=doc&id=2694898.1
Enterprise Manager for Peoplesoft, version 13.4.1.1https://support.oracle.com/rs?type=doc&id=2694898.1
Enterprise Manager for Storage Management, versions 13.3.0.0, 13.4.0.0https://support.oracle.com/rs?type=doc&id=2694898.1
Enterprise Manager Ops Center, version 12.4.0.0https://support.oracle.com/rs?type=doc&id=2694898.1
Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers, versions prior to XCP2362, prior to XCP3090https://support.oracle.com/rs?type=doc&id=2711819.1
Fujitsu M12-1, M12-2, M12-2S Servers, versions prior to XCP3090https://support.oracle.com/rs?type=doc&id=2711819.1
Hyperion Analytic Provider Services, version 11.1.2.4https://support.oracle.com/rs?type=doc&id=2694898.1
Hyperion BI+, version 11.1.2.4https://support.oracle.com/rs?type=doc&id=2694898.1
Hyperion Essbase, version 11.1.2.4https://support.oracle.com/rs?type=doc&id=2694898.1
Hyperion Infrastructure Technology, version 11.1.2.4https://support.oracle.com/rs?type=doc&id=2694898.1
Hyperion Lifecycle Management, version 11.1.2.4https://support.oracle.com/rs?type=doc&id=2694898.1
Hyperion Planning, version 11.1.2.4https://support.oracle.com/rs?type=doc&id=2694898.1
Identity Manager Connector, version 9.0https://support.oracle.com/rs?type=doc&id=2694898.1
Instantis EnterpriseTrack, versions 17.1, 17.2, 17.3https://support.oracle.com/rs?type=doc&id=2706889.1
Management Pack for Oracle GoldenGate, version 12.2.1.2.0https://support.oracle.com/rs?type=doc&id=2694898.1
MySQL Cluster, versions 7.3.30 and prior, 7.4.29 and prior, 7.5.19 and prior, 7.6.15 and prior, 8.0.21 and priorhttps://support.oracle.com/rs?type=doc&id=2711190.1
MySQL Enterprise Monitor, versions 8.0.21 and priorhttps://support.oracle.com/rs?type=doc&id=2711190.1
MySQL Server, versions 5.6.49 and prior, 5.7.31 and prior, 8.0.21 and priorhttps://support.oracle.com/rs?type=doc&id=2711190.1
MySQL Workbench, versions 8.0.21 and priorhttps://support.oracle.com/rs?type=doc&id=2711190.1
Oracle Access Manager, version 11.1.2.3.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Agile PLM, versions 9.3.3, 9.3.5, 9.3.6https://support.oracle.com/rs?type=doc&id=2711605.1
Oracle Agile Product Lifecycle Management for Process, version 6.2.0.0https://support.oracle.com/rs?type=doc&id=2711605.1
Oracle Application Express, versions prior to 20.2https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Application Testing Suite, version 13.3.0.1https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Banking Corporate Lending, versions 12.3.0, 14.0.0-14.4.0https://support.oracle.com
Oracle Banking Digital Experience, versions 18.1, 18.2, 18.3, 19.1, 19.2, 20.1https://support.oracle.com
Oracle Banking Payments, versions 14.1.0-14.4.0https://support.oracle.com
Oracle Banking Platform, versions 2.4.0-2.10.0https://support.oracle.com/rs?type=doc&id=2715770.1
Oracle BI Publisher, versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Business Intelligence Enterprise Edition, versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Business Process Management Suite, versions 12.2.1.3.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Communications Application Session Controller, versions 3.8m0, 3.9m0p1https://support.oracle.com/rs?type=doc&id=2714788.1
Oracle Communications Billing and Revenue Management, versions 7.5.0.23.0, 12.0.0.2.0, 12.0.0.3.0https://support.oracle.com/rs?type=doc&id=2713777.1
Oracle Communications BRM – Elastic Charging Engine, versions 11.3.0.9.0, 12.0.0.3.0https://support.oracle.com/rs?type=doc&id=2713777.1
Oracle Communications Diameter Signaling Router (DSR), versions 8.0.0.0-8.4.0.5, [IDIH] 8.0.0-8.2.2https://support.oracle.com/rs?type=doc&id=2714789.1
Oracle Communications EAGLE Software, versions 46.6.0-46.8.2https://support.oracle.com/rs?type=doc&id=2714787.1
Oracle Communications Element Manager, versions 8.2.0-8.2.2https://support.oracle.com/rs?type=doc&id=2714763.1
Oracle Communications Evolved Communications Application Server, version 7.1https://support.oracle.com/rs?type=doc&id=2714792.1
Oracle Communications Messaging Server, version 8.1https://support.oracle.com/rs?type=doc&id=2713779.1
Oracle Communications Offline Mediation Controller, version 12.0.0.3.0https://support.oracle.com/rs?type=doc&id=2713303.1
Oracle Communications Services Gatekeeper, version 7https://support.oracle.com/rs?type=doc&id=2714790.1
Oracle Communications Session Border Controller, versions 8.2-8.4https://support.oracle.com/rs?type=doc&id=2712893.1
Oracle Communications Session Report Manager, versions 8.2.0-8.2.2https://support.oracle.com/rs?type=doc&id=2714764.1
Oracle Communications Session Route Manager, versions 8.2.0-8.2.2https://support.oracle.com/rs?type=doc&id=2714796.1
Oracle Communications Unified Inventory Management, versions 7.3.0, 7.4.0https://support.oracle.com/rs?type=doc&id=2714988.1
Oracle Communications WebRTC Session Controller, version 7.2https://support.oracle.com/rs?type=doc&id=2714791.1
Oracle Data Integrator, versions 11.1.1.9.0, 12.2.1.3.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19chttps://support.oracle.com/rs?type=doc&id=2694898.1
Oracle E-Business Suite, versions 12.1.1-12.1.3, 12.2.3-12.2.10https://support.oracle.com/rs?type=doc&id=2707309.1
Oracle Endeca Information Discovery Integrator, version 3.2.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Endeca Information Discovery Studio, version 3.2.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Enterprise Repository, version 11.1.1.7.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Enterprise Session Border Controller, version 8.4https://support.oracle.com/rs?type=doc&id= 2712894.1
Oracle Financial Services Analytical Applications Infrastructure, versions 8.0.6-8.1.0https://support.oracle.com/rs?type=doc&id=2704305.1
Oracle Financial Services Analytical Applications Reconciliation Framework, versions 8.0.6-8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2705512.1
Oracle Financial Services Asset Liability Management, versions 8.0.6, 8.0.7, 8.1.0https://support.oracle.com/rs?type=doc&id=2704748.1
Oracle Financial Services Balance Sheet Planning, version 8.0.8https://support.oracle.com/rs?type=doc&id=2705665.1
Oracle Financial Services Basel Regulatory Capital Basic, versions 8.0.6-8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2705511.1
Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach, versions 8.0.6-8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2705511.1
Oracle Financial Services Data Foundation, versions 8.0.6-8.1.0https://support.oracle.com/rs?type=doc&id=2705681.1
Oracle Financial Services Data Governance for US Regulatory Reporting, versions 8.0.6-8.0.9https://support.oracle.com/rs?type=doc&id=2705513.1
Oracle Financial Services Data Integration Hub, versions 8.0.6, 8.0.7, 8.1.0https://support.oracle.com/rs?type=doc&id=2705531.1
Oracle Financial Services Funds Transfer Pricing, versions 8.0.6, 8.0.7, 8.1.0https://support.oracle.com/rs?type=doc&id=2705654.1
Oracle Financial Services Hedge Management and IFRS Valuations, versions 8.0.6-8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2704293.1
Oracle Financial Services Institutional Performance Analytics, versions 8.0.6, 8.0.7, 8.1.0, 8.7.0https://support.oracle.com/rs?type=doc&id=2705654.1
Oracle Financial Services Liquidity Risk Management, version 8.0.6https://support.oracle.com/rs?type=doc&id=2704898.1
Oracle Financial Services Liquidity Risk Measurement and Management, versions 8.0.7, 8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2704901.1
Oracle Financial Services Loan Loss Forecasting and Provisioning, versions 8.0.6-8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2719496.1
Oracle Financial Services Market Risk Measurement and Management, versions 8.0.6, 8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2704899.1
Oracle Financial Services Price Creation and Discovery, versions 8.0.6, 8.0.7https://support.oracle.com/rs?type=doc&id=2705667.1
Oracle Financial Services Profitability Management, versions 8.0.6, 8.0.7, 8.1.0https://support.oracle.com/rs?type=doc&id=2705654.1
Oracle Financial Services Regulatory Reporting for European Banking Authority, versions 8.0.6-8.1.0https://support.oracle.com/rs?type=doc&id=2705736.1
Oracle Financial Services Regulatory Reporting for US Federal Reserve, versions 8.0.6-8.0.9https://support.oracle.com/rs?type=doc&id=2705700.1
Oracle Financial Services Regulatory Reporting with AgileREPORTER, version 8.0.9.2.0https://support.oracle.com/rs?type=doc&id=2706757.1
Oracle Financial Services Retail Customer Analytics, version 8.0.6https://support.oracle.com/rs?type=doc&id=2705668.1
Oracle FLEXCUBE Core Banking, versions 5.2.0, 11.5.0-11.7.0https://support.oracle.com
Oracle FLEXCUBE Direct Banking, versions 12.0.1, 12.0.2, 12.0.3https://support.oracle.com
Oracle FLEXCUBE Private Banking, versions 12.0.0, 12.1.0https://support.oracle.com
Oracle FLEXCUBE Universal Banking, versions 12.3.0, 14.0.0-14.4.0https://support.oracle.com
Oracle GoldenGate Application Adapters, versions 12.3.2.1.0, 19.1.0.0.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle GraalVM Enterprise Edition, versions 19.3.3, 20.2.0https://support.oracle.com/rs?type=doc&id=2711576.1
Oracle Health Sciences Empirica Signal, version 9.0https://support.oracle.com/rs?type=doc&id=2711188.1
Oracle Healthcare Data Repository, version 7.0.1https://support.oracle.com/rs?type=doc&id=2711188.1
Oracle Healthcare Foundation, versions 7.1.1, 7.2.0, 7.2.1, 7.3.0https://support.oracle.com/rs?type=doc&id=2711188.1
Oracle Hospitality Guest Access, versions 4.2.0, 4.2.1https://support.oracle.com/rs?type=doc&id=2702050.1
Oracle Hospitality Materials Control, version 18.1https://support.oracle.com/rs?type=doc&id=2712740.1
Oracle Hospitality OPERA 5 Property Services, versions 5.5, 5.6https://support.oracle.com/rs?type=doc&id=2712344.1
Oracle Hospitality Reporting and Analytics, version 9.1.0https://support.oracle.com/rs?type=doc&id=2703386.1
Oracle Hospitality RES 3700, version 5.7https://support.oracle.com/rs?type=doc&id=2712880.1
Oracle Hospitality Simphony, versions 18.1, 18.2, 19.1.0-19.1.2https://support.oracle.com/rs?type=doc&id=2703395.1
Oracle Hospitality Suite8, versions 8.10.2, 8.11-8.15https://support.oracle.com/rs?type=doc&id=2702015.1
Oracle HTTP Server, versions 12.2.1.3.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Insurance Accounting Analyzer, version 8.0.9https://support.oracle.com/rs?type=doc&id=2704294.1
Oracle Insurance Allocation Manager for Enterprise Profitability, versions 8.0.8, 8.1.0https://support.oracle.com/rs?type=doc&id=2711851.1
Oracle Insurance Data Foundation, versions 8.0.6-8.1.0https://support.oracle.com/rs?type=doc&id=2705680.1
Oracle Insurance Insbridge Rating and Underwriting, versions 5.0.0.0-5.6.0.0, 5.6.1.0https://support.oracle.com/rs?type=doc&id=2713244.1
Oracle Insurance Policy Administration J2EE, versions 10.2.0.37, 10.2.4.12, 11.0.2.25, 11.1.0.15, 11.2.0.26, 11.2.2.0https://support.oracle.com/rs?type=doc&id=2713244.1
Oracle Insurance Rules Palette, versions 10.2.0.37, 10.2.4.12, 11.0.2.25, 11.1.0.15, 11.2.0.26https://support.oracle.com/rs?type=doc&id=2713244.1
Oracle Java SE, versions 7u271, 8u261, 11.0.8, 15https://support.oracle.com/rs?type=doc&id=2708527.1
Oracle Java SE Embedded, version 8u261https://support.oracle.com/rs?type=doc&id=2708527.1
Oracle JDeveloper, versions 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Managed File Transfer, versions 12.2.1.3.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Outside In Technology, versions 8.5.4, 8.5.5https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Policy Automation, versions 12.2.0-12.2.20https://support.oracle.com/rs?type=doc&id=2715655.1
Oracle Policy Automation Connector for Siebel, version 10.4.6https://support.oracle.com/rs?type=doc&id=2715655.1
Oracle Policy Automation for Mobile Devices, versions 12.2.0-12.2.20https://support.oracle.com/rs?type=doc&id=2715655.1
Oracle REST Data Services, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c, [Standalone ORDS] prior to 20.2.1https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Retail Advanced Inventory Planning, version 14.1https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Assortment Planning, versions 15.0.3.0, 16.0.3.0https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Back Office, versions 14.0, 14.1https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Bulk Data Integration, versions 15.0.3.0, 16.0.3.0https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Central Office, versions 14.0, 14.1https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Customer Management and Segmentation Foundation, versions 18.0, 19.0https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Integration Bus, versions 14.1, 15.0, 16.0https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Order Broker, versions 15.0, 16.0, 18.0, 19.0, 19.1, 19.2, 19.3https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Point-of-Service, versions 14.0, 14.1https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Predictive Application Server, versions 14.1.3.0, 15.0.3.0, 16.0.3.0https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Price Management, versions 14.0.4, 14.1.3.0, 15.0.3.0, 16.0.3.0https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Returns Management, versions 14.0, 14.1https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Service Backbone, versions 14.1, 15.0, 16.0https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Retail Xstore Point of Service, versions 15.0.3, 16.0.5, 17.0.3, 18.0.2, 19.0.1https://support.oracle.com/rs?type=doc&id=2706946.1
Oracle Solaris, versions 10, 11https://support.oracle.com/rs?type=doc&id=2711819.1
Oracle TimesTen In-Memory Database, versions prior to 11.2.2.8.49, prior to 18.1.3.1.0, prior to 18.1.4.1.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle Transportation Management, version 6.3.7https://support.oracle.com/rs?type=doc&id=2711605.1
Oracle Utilities Framework, versions 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0https://support.oracle.com/rs?type=doc&id=2712417.1
Oracle VM VirtualBox, versions prior to 6.1.16https://support.oracle.com/rs?type=doc&id=2712499.1
Oracle WebCenter Portal, versions 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle WebLogic Server, versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0https://support.oracle.com/rs?type=doc&id=2694898.1
Oracle ZFS Storage Appliance Kit, version 8.8https://support.oracle.com/rs?type=doc&id=2711819.1
PeopleSoft Enterprise HCM Global Payroll Core, version 9.2https://support.oracle.com/rs?type=doc&id=2711230.1
PeopleSoft Enterprise PeopleTools, versions 8.56, 8.57, 8.58https://support.oracle.com/rs?type=doc&id=2711230.1
PeopleSoft Enterprise SCM eSupplier Connection, version 9.2https://support.oracle.com/rs?type=doc&id=2711230.1
Primavera Gateway, versions 16.2.0-16.2.11, 17.12.0-17.12.8https://support.oracle.com/rs?type=doc&id=2706889.1
Primavera Unifier, versions 16.1, 16.2, 17.7-17.12, 18.8, 19.12https://support.oracle.com/rs?type=doc&id=2706889.1
Siebel Applications, versions 20.7, 20.8https://support.oracle.com/rs?type=doc&id=2711230.1

Spread the word. Share this post!

Meet The Author

威胁通告类文章

Leave Comment