首页  普法课堂

Oracle 2023年7月补丁日多产品安全漏洞风险通告

发布时间:2023-09-08 12:19:58 作者:admin

Oracle官方发布了2023年7月的关键安全补丁集合更新CPU(Critical Patch Update),修复了多个漏洞包括CVE-2023-26119、CVE-2023-1436、CVE-2023-22040、CVE-2023-22053等。大部分为第三组件漏洞,其中Oracle WebLogic Server安全特性绕过漏洞(CVE-2023-22040)影响相对较大。根据目前已有信息研判本次漏洞危害性一般,建议排期逐步修复应用7月关键安全补丁集合(CPU)。

CVE编号影响组件协议是否远程未授权利用CVSS受影响版本
CVE-2023-22040Oracle WebLogic Server(core)Multiple6.512.2.1.4.0, 14.1.1.0.0
CVE-2023-22031Oracle WebLogic Server(Core)T3, IIOP4.412.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
CVE-2023-22053MySQL Server: Client programsMySQL Protocol5.95.7.42 and prior, 8.0.33 and prior
CVE-2023-22008MySQL Server: InnoDBMySQL Protocol4.98.0.33 and prior
CVE-2023-22046MySQL Server: Server: OptimizerMySQL Protocol4.98.0.33 and prior
CVE-2023-22054MySQL Server: Server: OptimizerMySQL Protocol4.98.0.33 and prior
CVE-2023-22056MySQL Server: Server: OptimizerMySQL Protocol4.98.0.33 and prior
CVE-2023-21950MySQL Server: Server: ReplicationMySQL Protocol4.98.0.27 and prior
CVE-2023-22007MySQL Server: Server: ReplicationMySQL Protocol4.95.7.41 and prior, 8.0.32 and prior
CVE-2023-22057MySQL Server: Server: ReplicationMySQL Protocol4.98.0.33 and prior
CVE-2023-22033MySQL Server: InnoDBMySQL Protocol4.48.0.33 and prior
CVE-2023-22058MySQL Server: Server: DDLMySQL Protocol4.48.0.33 and prior
CVE-2023-22005MySQL Server: Server: ReplicationMySQL Protocol4.48.0.33 and prior