近日,Oracle官方发布了多个安全漏洞的公告,包括OracleCommunications 安全漏洞(CNNVD-202201-1572、CVE-2022-21395)、Oracle Enterprise ManagerBase Platform安全漏洞(CNNVD-202201-1511、CVE-2022-21392)等123个漏洞。成功利用上述漏洞的攻击者可以在目标系统上执行任意代码、获取用户数据,提升权限等。Oracle多个产品和系统受漏洞影响。目前,Oracle官方已经发布了漏洞修复补丁,建议用户及时确认是否受到漏洞影响,尽快采取修补措施。

一、 漏洞介绍

2022年1月18日,Oracle发布了2022年1月份安全更新,共123个漏洞的补丁程序,CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Oracle Mysql 和 Mysql 组件、Oracle PeopleSoft Enterprise PeopleTools、OracleWebLogic Server、Oracle VM VirtualBox、Oracle Enterprise Manager Base、OracleSolaris等。CNNVD对其危害等级进行了评价,其中高危漏洞6个,中危漏洞96个,低危漏洞21个。Oracle多个产品和系统版本受漏洞影响,具体影响范围可访问https://www.oracle.com/security-alerts/cpujan2022.html查询。

二、漏洞详情

此次更新共包括123个漏洞的补丁程序,其中高危漏洞6个,中危漏洞96个,低危漏洞21个。

序号

漏洞名称

CNNVD编号

CVE编号

危害等级

官方链接

1

Oracle Communications 安全漏洞

CNNVD-202201-1572

CVE-2022-21395

高危

https://www.oracle.com/security-alerts/cpujan2022.html

2

Oracle Communications 安全漏洞

CNNVD-202201-1579

CVE-2022-21382

高危

https://www.oracle.com/security-alerts/cpujan2022.html

3

Oracle Enterprise Manager Base Platform安全漏洞

CNNVD-202201-1511

CVE-2022-21392

高危

https://www.oracle.com/security-alerts/cpujan2022.html

4

Oracle E-Business Suite 安全漏洞

CNNVD-202201-1524

CVE-2022-21251

高危

https://www.oracle.com/security-alerts/cpujan2022.html

5

Oracle Access Management 输入验证错误漏洞

CNNVD-202201-1433

CVE-2021-35587

高危

https://www.oracle.com/security-alerts/cpujan2022.html

6

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1434

CVE-2022-21306

高危

https://www.oracle.com/security-alerts/cpujan2022.html

7

Oracle Communications 安全漏洞

CNNVD-202201-1559

CVE-2022-21403

中危

https://www.oracle.com/security-alerts/cpujan2022.html

8

Oracle Communications 安全漏洞

CNNVD-202201-1560

CVE-2022-21401

中危

https://www.oracle.com/security-alerts/cpujan2022.html

9

Oracle Communications 安全漏洞

CNNVD-202201-1567

CVE-2022-21399

中危

https://www.oracle.com/security-alerts/cpujan2022.html

10

Oracle Communications 安全漏洞

CNNVD-202201-1586

CVE-2022-21338

中危

https://www.oracle.com/security-alerts/cpujan2022.html

11

MySQL Server 输入验证错误漏洞

CNNVD-202201-1588

CVE-2022-21351

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

12

MySQL Server 输入验证错误漏洞

CNNVD-202201-1589

CVE-2022-21352

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

13

MySQL Server 输入验证错误漏洞

CNNVD-202201-1590

CVE-2022-21278

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

14

Oracle MySQL Server 输入验证错误漏洞

CNNVD-202201-1591

CVE-2022-21358

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

15

MySQL Server 输入验证错误漏洞

CNNVD-202201-1592

CVE-2022-21301

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

16

Oracle MySQL Server 输入验证错误漏洞

CNNVD-202201-1593

CVE-2022-21378

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

17

MySQL Server 输入验证错误漏洞

CNNVD-202201-1594

CVE-2022-21367

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

18

MySQL Server 输入验证错误漏洞

CNNVD-202201-1595

CVE-2022-21254

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

19

Oracle MySQL Server 输入验证错误漏洞

CNNVD-202201-1596

CVE-2022-21302

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

20

MySQL Server 输入验证错误漏洞

CNNVD-202201-1597

CVE-2022-21348

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

21

MySQL Server 输入验证错误漏洞

CNNVD-202201-1598

CVE-2022-21256

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

22

MySQL Server 输入验证错误漏洞

CNNVD-202201-1599

CVE-2022-21270

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

23

MySQL Server 输入验证错误漏洞

CNNVD-202201-1600

CVE-2022-21379

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

24

MySQL Server 输入验证错误漏洞

CNNVD-202201-1601

CVE-2022-21362

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

25

MySQL Server 输入验证错误漏洞

CNNVD-202201-1602

CVE-2022-21253

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

26

MySQL Server 输入验证错误漏洞

CNNVD-202201-1603

CVE-2022-21374

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

27

MySQL Server 输入验证错误漏洞

CNNVD-202201-1604

CVE-2022-21297

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

28

MySQL Server 输入验证错误漏洞

CNNVD-202201-1605

CVE-2022-21264

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

29

MySQL Server 输入验证错误漏洞

CNNVD-202201-1606

CVE-2022-21339

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

30

MySQL Server 输入验证错误漏洞

CNNVD-202201-1607

CVE-2022-21342

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

31

MySQL Server 输入验证错误漏洞

CNNVD-202201-1608

CVE-2022-21344

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

32

MySQL Server 输入验证错误漏洞

CNNVD-202201-1609

CVE-2022-21370

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

33

MySQL Server 输入验证错误漏洞

CNNVD-202201-1610

CVE-2022-21368

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

34

MySQL Server 输入验证错误漏洞

CNNVD-202201-1615

CVE-2022-21279

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

35

MySQL Server 输入验证错误漏洞

CNNVD-202201-1616

CVE-2022-21280

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

36

MySQL Server 输入验证错误漏洞

CNNVD-202201-1617

CVE-2022-21285

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

37

MySQL Server 输入验证错误漏洞

CNNVD-202201-1618

CVE-2022-21284

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

38

MySQL Server 输入验证错误漏洞

CNNVD-202201-1619

CVE-2022-21286

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

39

MySQL Server 输入验证错误漏洞

CNNVD-202201-1620

CVE-2022-21287

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

40

MySQL Server 输入验证错误漏洞

CNNVD-202201-1621

CVE-2022-21289

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

41

MySQL Server 输入验证错误漏洞

CNNVD-202201-1622

CVE-2022-21290

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

42

MySQL Server 输入验证错误漏洞

CNNVD-202201-1623

CVE-2022-21307

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

43

MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1624

CVE-2022-21288

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

44

MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1625

CVE-2022-21308

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

45

MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1626

CVE-2022-21309

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

46

MySQL Server 输入验证错误漏洞

CNNVD-202201-1627

CVE-2022-21363

中危

https://www.cybersecurity-help.cz/vdb/SB2022011905

47

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1448

CVE-2022-21386

中危

https://www.oracle.com/

48

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1450

CVE-2022-21314

中危

https://www.oracle.com/

49

Oracle Solaris 访问控制错误漏洞

CNNVD-202201-1451

CVE-2021-43395

中危

https://www.oracle.com/

50

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1452

CVE-2022-21315

中危

https://www.oracle.com/

51

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1453

CVE-2022-21316

中危

https://www.oracle.com/

52

Oracle PeopleSoft Enterprise PeopleTools 访问控制错误漏洞

CNNVD-202201-1454

CVE-2022-21364

中危

https://www.oracle.com/

53

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1455

CVE-2022-21310

中危

https://www.oracle.com/security-alerts/cpujan2022.html

54

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1456

CVE-2022-21318

中危

https://www.oracle.com/security-alerts/cpujan2022.html

55

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1460

CVE-2022-21320

中危

https://www.oracle.com/security-alerts/cpujan2022.html

56

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1464

CVE-2022-21327

中危

https://www.oracle.com/security-alerts/cpujan2022.html

57

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1466

CVE-2022-21328

中危

https://www.oracle.com/security-alerts/cpujan2022.html

58

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1467

CVE-2022-21329

中危

https://www.oracle.com/security-alerts/cpujan2022.html

59

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1469

CVE-2022-21326

中危

https://www.oracle.com/security-alerts/cpujan2022.html

60

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1470

CVE-2022-21330

中危

https://www.oracle.com/security-alerts/cpujan2022.html

61

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1472

CVE-2022-21332

中危

https://www.oracle.com/security-alerts/cpujan2022.html

62

MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1473

CVE-2022-21334

中危

https://www.oracle.com/security-alerts/cpujan2022.html

63

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1475

CVE-2022-21335

中危

https://www.oracle.com/security-alerts/cpujan2022.html

64

MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1478

CVE-2022-21336

中危

https://www.oracle.com/security-alerts/cpujan2022.html

65

MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1479

CVE-2022-21337

中危

https://www.oracle.com/security-alerts/cpujan2022.html

66

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1481

CVE-2022-21322

中危

https://www.oracle.com/security-alerts/cpujan2022.html

67

Oracle MySQL Cluster 输入验证错误漏洞

CNNVD-202201-1482

CVE-2022-21356

中危

https://www.oracle.com/security-alerts/cpujan2022.html

68

Oracle GraalVM 输入验证错误漏洞

CNNVD-202201-1483

CVE-2022-21349

中危

http://www.oracle.com/security-alerts/cpujan2022.html?3082

69

Oracle GraalVM 输入验证错误漏洞

CNNVD-202201-1484

CVE-2022-21291

中危

http://www.oracle.com/security-alerts/cpujan2022.html?3082

70

Oracle GraalVM 输入验证错误漏洞

CNNVD-202201-1485

CVE-2022-21365

中危

http://www.oracle.com/security-alerts/cpujan2022.html?3082

71

Oracle GraalVM 输入验证错误漏洞

CNNVD-202201-1486

CVE-2022-21277

中危

http://www.oracle.com/security-alerts/cpujan2022.html?3082

72

Oracle GraalVM 输入验证错误漏洞

CNNVD-202201-1487

CVE-2022-21360

中危

https://www.oracle.com/security-alerts/cpujan2022.html

73

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1490

CVE-2022-21294

中危

https://www.oracle.com/security-alerts/cpujan2022.html

74

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1491

CVE-2022-21305

中危

https://www.oracle.com/security-alerts/cpujan2022.html

75

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1493

CVE-2022-21282

中危

https://www.oracle.com/security-alerts/cpujan2022.html

76

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1494

CVE-2022-21293

中危

https://www.oracle.com/security-alerts/cpujan2022.html

77

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1495

CVE-2022-21299

中危

https://www.oracle.com/security-alerts/cpujan2022.html

78

Oracle Solaris 输入验证错误漏洞

CNNVD-202201-1496

CVE-2022-21271

中危

https://www.oracle.com/security-alerts/cpujan2022.html

79

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1498

CVE-2022-21340

中危

https://www.oracle.com/security-alerts/cpujan2022.html

80

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1499

CVE-2022-21341

中危

https://www.oracle.com/security-alerts/cpujan2022.html

81

Oracle E-Business Suite 安全漏洞

CNNVD-202201-1517

CVE-2022-21373

中危

https://www.oracle.com/security-alerts/cpujan2022.html

82

Oracle Communications 安全漏洞

CNNVD-202201-1527

CVE-2022-21383

中危

https://www.oracle.com/security-alerts/cpujan2022.html

83

Oracle Communications 安全漏洞

CNNVD-202201-1531

CVE-2022-21402

中危

https://www.oracle.com/security-alerts/cpujan2022.html

84

Oracle Communications 安全漏洞

CNNVD-202201-1545

CVE-2022-21397

中危

https://www.oracle.com/security-alerts/cpujan2022.html

85

Oracle Communications 安全漏洞

CNNVD-202201-1546

CVE-2022-21396

中危

https://www.oracle.com/security-alerts/cpujan2022.html

86

Oracle Communications 安全漏洞

CNNVD-202201-1547

CVE-2022-21246

中危

https://www.oracle.com/security-alerts/cpujan2022.html

87

Oracle Communications 安全漏洞

CNNVD-202201-1553

CVE-2022-21381

中危

https://www.oracle.com/security-alerts/cpujan2022.html

88

MySQL Server 输入验证错误漏洞

CNNVD-202201-1429

CVE-2022-21303

中危

https://www.oracle.com/security-alerts/cpujan2022.html

89

Oracle MySQL Server 输入验证错误漏洞

CNNVD-202201-1430

CVE-2022-21304

中危

https://www.oracle.com/security-alerts/cpujan2022.html

90

Oracle VM VirtualBox 输入验证错误漏洞

CNNVD-202201-1432

CVE-2022-21394

中危

https://www.oracle.com/security-alerts/cpujan2022.html

91

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1435

CVE-2022-21292

中危

https://www.oracle.com/security-alerts/cpujan2022.html

92

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1436

CVE-2022-21371

中危

https://www.oracle.com/security-alerts/cpujan2022.html

93

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1437

CVE-2022-21252

中危

https://www.oracle.com/security-alerts/cpujan2022.html

94

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1438

CVE-2022-21347

中危

https://www.oracle.com/security-alerts/cpujan2022.html

95

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1439

CVE-2022-21350

中危

https://www.oracle.com/security-alerts/cpujan2022.html

96

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1440

CVE-2022-21353

中危

https://www.oracle.com/security-alerts/cpujan2022.html

97

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1441

CVE-2022-21361

中危

https://www.oracle.com/security-alerts/cpujan2022.html

98

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1442

CVE-2022-21257

中危

https://www.oracle.com/security-alerts/cpujan2022.html

99

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1443

CVE-2022-21258

中危

https://www.oracle.com/

100

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1444

CVE-2022-21260

中危

https://www.oracle.com/

101

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1445

CVE-2022-21259

中危

https://www.oracle.com/

102

Oracle WebLogic Server 输入验证错误漏洞

CNNVD-202201-1446

CVE-2022-21261

中危

https://www.oracle.com/

103

MySQL Server 输入验证错误漏洞

CNNVD-202201-1611

CVE-2022-21245

低危

https://www.cybersecurity-help.cz/vdb/SB2022011905

104

MySQL Server 输入验证错误漏洞

CNNVD-202201-1612

CVE-2022-21265

低危

https://www.cybersecurity-help.cz/vdb/SB2022011905

105

MySQL Server 缓冲区错误漏洞

CNNVD-202201-1613

CVE-2022-21249

低危

https://www.cybersecurity-help.cz/vdb/SB2022011905

106

MySQL Server 缓冲区错误漏洞

CNNVD-202201-1614

CVE-2022-21372

低危

https://www.cybersecurity-help.cz/vdb/SB2022011905

107

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1457

CVE-2022-21355

低危

https://www.oracle.com/security-alerts/cpujan2022.html

108

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1458

CVE-2022-21333

低危

https://www.oracle.com/security-alerts/cpujan2022.html

109

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1459

CVE-2022-21331

低危

https://www.oracle.com/security-alerts/cpujan2022.html

110

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1461

CVE-2022-21325

低危

https://www.oracle.com/security-alerts/cpujan2022.html

111

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1462

CVE-2022-21357

低危

https://www.oracle.com/security-alerts/cpujan2022.html

112

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1463

CVE-2022-21324

低危

https://www.oracle.com/security-alerts/cpujan2022.html

113

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1465

CVE-2022-21323

低危

https://www.oracle.com/security-alerts/cpujan2022.html

114

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1468

CVE-2022-21321

低危

https://www.oracle.com/security-alerts/cpujan2022.html

115

MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1471

CVE-2022-21319

低危

https://www.oracle.com/security-alerts/cpujan2022.html

116

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1474

CVE-2022-21317

低危

https://www.oracle.com/security-alerts/cpujan2022.html

117

MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1476

CVE-2022-21313

低危

https://www.oracle.com/security-alerts/cpujan2022.html

118

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1477

CVE-2022-21312

低危

https://www.oracle.com/security-alerts/cpujan2022.html

119

Oracle MySQL Cluster 缓冲区错误漏洞

CNNVD-202201-1480

CVE-2022-21311

低危

https://www.oracle.com/security-alerts/cpujan2022.html

120

Oracle Java SE 输入验证错误漏洞

CNNVD-202201-1500

CVE-2022-21248

低危

https://www.oracle.com/security-alerts/cpujan2022.html

121

Oracle Database Server 输入验证错误漏洞

CNNVD-202201-1426

CVE-2022-21393

低危

https://www.oracle.com/security-alerts/cpujan2022.html

122

Oracle Database Server 输入验证错误漏洞

CNNVD-202201-1427

CVE-2022-21247

低危

https://www.oracle.com/security-alerts/cpujan2022.html

123

Oracle VM VirtualBox 输入验证错误漏洞

CNNVD-202201-1431

CVE-2022-21295

低危

https://www.oracle.com/security-alerts/cpujan2022.html

三、修复建议

目前,Oracle官方已经发布补丁修复了上述漏洞,建议用户及时确认漏洞影响,尽快采取修补措施。Oracle官方补丁下载地址:

https://www.oracle.com/security-alerts/cpujan2022.html

CNNVD将继续跟踪上述漏洞的相关情况,及时发布相关信息。如有需要,可与CNNVD联系。联系方式: cnnvdvul@itsec.gov.cn

声明:本文来自CNNVD安全动态,版权归作者所有。文章内容仅代表作者独立观点,不代表安全内参立场,转载目的在于传递更多信息。如有侵权,请联系 anquanneican@163.com。