2018年8月來自Oracle 的重要告警
Oracle 在 8 月接連發布了兩個安全性告警, 2018 年 8 月 10 日 CVE-2018-3110 議題 Oracle 最新發佈程式安全漏洞示警請留意 ”This Security Alert addresses an Oracle Database vulnerability in versions 11.2.0.4 and 12.2.0.1 on Windows . CVE-2018-3110 has a CVSS v3 base score of 9.9 , and can result in complete compromise of the Oracle Database and shell access to the underlying server. CVE-2018-3110 also affects Oracle Database version 12.1.0.2 on Windows as well as Oracle Database on Linux and Unix , however patches for those versions and platforms were included in the July 2018 CPU”. 2.5 Database OJVM Security fix CVE-2018-3110 now updated for Database versions Fix for CVE-2018-3110 is included in Database OJVM patches for 18, 12.2.0.1, 12.1.0.2 and 11.2.0.4 and is documented in their respective tables in section '3.1.4 Oracle Database' as of 10-Aug-2018. 這議題是 Java 漏洞,只要 Oracle DB 還沒更新到 20180717 Patch 的用戶端都會受影響,主要影響 Oracle DB 內建的 OJVM ,建議除了更新 20180717 Patch ,也順便更新 OJVM Patch 。 ...