تنبيه Oracle
3170تاريخ التحذير
مستوى الخطورة
رقم التحذير
القطاع المستهدف
20 إبريل, 2022
● عالٍ جدًا
2022-4689
الكل
أصدرت Oracle تحديثات لمعالجة عدة ثغرات في المنتجات التالية:
- Engineered Systems Utilities, نسخ 12.1.0.2, 19c, 21c
·
- Enterprise Manager Base Platform, نسخ 13.4.0.0, 13.5.0.0
·
- Enterprise Manager for Peoplesoft, نسخ 13.4.1.1, 13.5.1.1
·
- Enterprise Manager for Storage Management, نسخة13.4.0.0
·
- Enterprise Manager Ops Center, نسخة12.4.0.0
·
- Helidon, نسخ 1.4.7, 1.4.10, 2.0.0-RC1
·
- Instantis EnterpriseTrack, نسخ 17.1, 17.2, 17.3
·
- JD Edwards EnterpriseOne Tools, نسخ ما قبل 9.2.6.3
·
- JD Edwards World Security, نسخةA9.4
·
- Management Cloud Engine, نسخ 1.5.0 and prior
·
- Middleware Common Libraries and Tools, نسخ 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
·
- MySQL Cluster, نسخ 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior, 8.0.28 and prior
·
- MySQL Connectors, نسخ 8.0.28 and prior
·
- MySQL Enterprise Monitor, نسخ 8.0.29 and prior
·
- MySQL Server, نسخ 5.7.37 and prior, 8.0.28 and prior
·
- MySQL Workbench, نسخ 8.0.28 and prior
·
- Oracle Advanced Supply Chain Planning, نسخ 12.1, 12.2
·
- Oracle Agile Engineering Data Management, نسخة6.2.1.0
·
- Oracle Agile PLM, نسخة9.3.6
·
- Oracle Agile PLM MCAD Connector, نسخة3.6
·
- Oracle Application Express, نسخ ما قبل 22.1
·
- Oracle Application Testing Suite, نسخة13.3.0.1
·
- Oracle Autovue for Agile Product Lifecycle Management, نسخة21.0.2
·
- Oracle Banking Deposits and Lines of Credit Servicing, نسخة2.12.0
·
- Oracle Banking Enterprise Default Management, نسخ 2.7.1, 2.10.0, 2.12.0
·
- Oracle Banking Loans Servicing, نسخة2.12.0
·
- Oracle Banking Party Management, نسخة2.7.0
·
- Oracle Banking Payments, نسخة14.5
·
- Oracle Banking Platform, نسخ 2.6.2, 2.7.1, 2.12.0
·
- Oracle Banking Trade Finance, نسخة14.5
·
- Oracle Banking Treasury Management, نسخة14.5
·
- Oracle Blockchain Platform, نسخ ما قبل 21.1.2
·
- Oracle Business Intelligence Enterprise Edition, نسخ 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Business Process Management Suite, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Coherence, نسخ 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
·
- Oracle Commerce Guided Search, نسخة11.3.2
·
- Oracle Communications ASAP, نسخة7.3
·
- Oracle Communications Billing and Revenue Management, نسخ 12.0.0.4, 12.0.0.5
·
- Oracle Communications Cloud Native Core Automated Test Suite, نسخ 1.8.0, 1.9.0, 22.1.0
·
- Oracle Communications Cloud Native Core Binding Support Function, نسخة1.11.0
·
- Oracle Communications Cloud Native Core Console, نسخ 1.9.0, 22.1.0
·
- Oracle Communications Cloud Native Core Network Exposure Function, نسخة22.1.0
·
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment, نسخ 1.10.0, 22.1.0
·
- Oracle Communications Cloud Native Core Network Repository Function, نسخ 1.15.0, 1.15.1, 22.1.0
·
- Oracle Communications Cloud Native Core Network Slice Selection Function, نسخ 1.8.0, 22.1.0
·
- Oracle Communications Cloud Native Core Policy, نسخ 1.14.0, 1.15.0, 22.1.0
·
- Oracle Communications Cloud Native Core Security Edge Protection Proxy, نسخ 1.7.0, 22.1.0
·
- Oracle Communications Cloud Native Core Service Communication Proxy, نسخة1.15.0
·
- Oracle Communications Cloud Native Core Unified Data Repository, نسخ 1.15.0, 22.1.0
·
- Oracle Communications Contacts Server, نسخة8.0.0.6.0
·
- Oracle Communications Convergence, نسخ 3.0.2.2, 3.0.3.0
·
- Oracle Communications Convergent Charging Controller, نسخ 6.0.1.0.0, 12.0.1.0.0-12.0.4.0.0
·
- Oracle Communications Design Studio, نسخ 7.3.5, 7.4.0-7.4.2
·
- Oracle Communications Diameter Intelligence Hub, نسخ 8.0.0-8.2.3
·
- Oracle Communications Diameter Signaling Router, نسخة8.4.0.0
·
- Oracle Communications EAGLE Application Processor
·
- Oracle Communications EAGLE Element Management System, نسخة46.6
·
- Oracle Communications EAGLE FTP Table Base Retrieval, نسخة4.5
·
- Oracle Communications EAGLE LNP Application Processor, نسخ 10.1, 10.2
·
- Oracle Communications EAGLE Software, نسخ 46.7.0, 46.8.0-46.8.2, 46.9.1-46.9.3
·
- Oracle Communications Element Manager, نسخ ما قبل 9.0
·
- Oracle Communications Evolved Communications Application Server, نسخة7.1
·
- Oracle Communications Instant Messaging Server, نسخة10.0.1.5.0
·
- Oracle Communications Interactive Session Recorder, نسخة6.4
·
- Oracle Communications IP Service Activator, نسخة7.4.0
·
- Oracle Communications Messaging Server, نسخة8.1
·
- Oracle Communications MetaSolv Solution, نسخة6.3.1
·
- Oracle Communications Network Charging and Control, نسخ 6.0.1.0.0, 12.0.1.0.0-12.0.4.0.0
·
- Oracle Communications Network Integrity, نسخ 7.3.2, 7.3.5, 7.3.6
·
- Oracle Communications Operations Monitor, نسخ 4.3, 4.4, 5.0
·
- Oracle Communications Order and Service Management, نسخ 7.3, 7.4
·
- Oracle Communications Performance Intelligence Center (PIC) Software, نسخ 10.3.0.0.0-10.3.0.2.1, 10.4.0.1.0-10.4.0.3.1
·
- Oracle Communications Policy Management, نسخ 12.5.0.0.0, 12.6.0.0.0
·
- Oracle Communications Pricing Design Center, نسخ 12.0.0.4, 12.0.0.5
·
- Oracle Communications Services Gatekeeper, نسخة7.0.0.0.0
·
- Oracle Communications Session Border Controller, نسخ 8.4, 9.0
·
- Oracle Communications Session Report Manager, نسخ ما قبل 9.0
·
- Oracle Communications Session Route Manager, نسخ ما قبل 9.0
·
- Oracle Communications Unified Inventory Management, نسخ 7.4.1, 7.4.2
·
- Oracle Communications Unified Session Manager, نسخ 8.2.5, 8.4.5
·
- Oracle Communications User Data Repository, نسخة12.4
·
- Oracle Communications WebRTC Session Controller, نسخة7.2.1
·
- Oracle Data Integrator, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Database Server, نسخ 12.1.0.2, 19c, 21c
·
- Oracle Documaker, نسخ 12.6.0, 12.6.2-12.6.4, 12.7.0
·
- Oracle E-Business Suite, نسخ 12.2.4-12.2.11, [EBS Cloud Manager and Backup Module] ما قبل 22.1.1.1, [Enterprise Command Center] 7.0, [Enterprise Information Discovery] 7-9
·
- Oracle Enterprise Communications Broker, نسخ 3.2, 3.3
·
- Oracle Enterprise Session Border Controller, نسخ 8.4, 9.0
·
- Oracle Ethernet Switch ES1-24, نسخة1.3.1
·
- Oracle Ethernet Switch TOR-72, نسخة1.2.2
·
- Oracle Financial Services Analytical Applications Infrastructure, نسخ 8.0.6.0-8.0.9.0, 8.1.0.0-8.1.2.0
·
- Oracle Financial Services Behavior Detection Platform, نسخ 8.0.6.0-8.0.8.0, 8.1.1.0, 8.1.1.1, 8.1.2.0
·
- Oracle Financial Services Enterprise Case Management, نسخ 8.0.7.1, 8.0.7.2, 8.0.8.0, 8.0.8.1, 8.1.1.0, 8.1.1.1, 8.1.2.0
·
- Oracle Financial Services Revenue Management and Billing, نسخ 2.7.0.0, 2.7.0.1, 2.8.0.0
·
- Oracle FLEXCUBE Universal Banking, نسخ 11.83.3, 12.1-12.4, 14.0-14.3, 14.5
·
- Oracle Global Lifecycle Management OPatch
·
- Oracle GoldenGate, نسخ ما قبل 12.3.0.1.2, ما قبل 23.1
·
- Oracle GoldenGate Application Adapters, نسخ ما قبل 23.1
·
- Oracle GoldenGate Big Data and Application Adapters, نسخ ما قبل 23.1
·
- Oracle GraalVM Enterprise Edition, نسخ 20.3.5, 21.3.1, 22.0.0.2
·
- Oracle Health Sciences Empirica Signal, نسخ 9.1.0.6, 9.2.0.0
·
- Oracle Health Sciences InForm, نسخ 6.2.1.1, 6.3.2.1, 7.0.0.0
·
- Oracle Health Sciences InForm Publisher, نسخ 6.2.1.1, 6.3.1.1
·
- Oracle Health Sciences Information Manager, نسخ 3.0.1-3.0.4
·
- Oracle Healthcare Data Repository, نسخ 8.1.0, 8.1.1
·
- Oracle Healthcare Foundation, نسخ 7.3.0.1-7.3.0.4
·
- Oracle Healthcare Master Person Index, نسخة5.0.1
·
- Oracle Healthcare Translational Research, نسخ 4.1.0, 4.1.1
·
- Oracle Hospitality Suite8, نسخ 8.10.2, 8.11.0-8.14.0
·
- Oracle Hospitality Token Proxy Service, نسخة19.2
·
- Oracle HTTP Server, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Hyperion BI+, نسخ ما قبل 11.2.8.0
·
- Oracle Hyperion Calculation Manager, نسخ ما قبل 11.2.8.0
·
- Oracle Hyperion Data Relationship Management, نسخ ما قبل 11.2.8.0, ما قبل 11.2.9.0
·
- Oracle Hyperion Financial Management, نسخ ما قبل 11.2.8.0
·
- Oracle Hyperion Infrastructure Technology, نسخ ما قبل 11.2.8.0
·
- Oracle Hyperion Planning, نسخ ما قبل 11.2.8.0
·
- Oracle Hyperion Profitability and Cost Management, نسخ ما قبل 11.2.8.0
·
- Oracle Hyperion Tax Provision, نسخ ما قبل 11.2.8.0
·
- Oracle Identity Management Suite, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Identity Manager Connector, نسخ 9.1.0, 11.1.1.5.0
·
- Oracle iLearning, نسخ 6.2, 6.3
·
- Oracle Insurance Data Gateway, نسخة1.0.1
·
- Oracle Insurance Insbridge Rating and Underwriting, نسخ 5.2.0, 5.4.0-5.6.0, 5.6.1
·
- Oracle Insurance Policy Administration, نسخ 11.0.2, 11.1.0, 11.2.8, 11.3.0, 11.3.1
·
- Oracle Insurance Rules Palette, نسخ 11.0.2, 11.1.0, 11.2.8, 11.3.0, 11.3.1
·
- Oracle Internet Directory, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Java SE, نسخ 7u331, 8u321, 11.0.14, 17.0.2, 18
·
- Oracle JDeveloper, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Managed File Transfer, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle Middleware Common Libraries and Tools, نسخة12.2.1.4.0
·
- Oracle NoSQL Database
·
- Oracle Outside In Technology, نسخة8.5.5
·
- Oracle Payment Interface, نسخ 19.1, 20.3
·
- Oracle Product Lifecycle Analytics, نسخة3.6.1.0
·
- Oracle REST Data Services, نسخ ما قبل 21.2
·
- Oracle Retail Bulk Data Integration, نسخة16.0.3
·
- Oracle Retail Customer Insights, نسخ 15.0.2, 16.0.2
·
- Oracle Retail Customer Management and Segmentation Foundation, نسخ 17.0-19.0
·
- Oracle Retail Data Extractor for Merchandising, نسخ 15.0.2, 16.0.2
·
- Oracle Retail EFTLink, نسخ 17.0.2, 18.0.1, 19.0.1, 20.0.1, 21.0.0
·
- Oracle Retail Extract Transform and Load, نسخة13.2.8
·
- Oracle Retail Financial Integration, نسخ 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0, 19.0.1
·
- Oracle Retail Integration Bus, نسخ 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0, 19.0.1
·
- Oracle Retail Invoice Matching, نسخة16.0.3
·
- Oracle Retail Merchandising System, نسخ 16.0.3, 19.0.1
·
- Oracle Retail Service Backbone, نسخ 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0, 19.0.1
·
- Oracle Retail Store Inventory Management, نسخ 14.0.4.13, 14.1.3.5, 14.1.3.14, 15.0.3.3, 15.0.3.8, 16.0.3.7
·
- Oracle Retail Xstore Office Cloud Service, نسخ 16.0.6, 17.0.4, 18.0.3, 19.0.2, 20.0.1
·
- Oracle Retail Xstore Point of Service, نسخ 16.0.6, 17.0.4, 18.0.3, 19.0.2, 20.0.1, 21.0.0
·
- Oracle SD-WAN Edge, نسخ 9.0, 9.1
·
- Oracle Secure Backup
·
- Oracle Secure Global Desktop, نسخة5.6
·
- Oracle Solaris, نسخة11
·
- Oracle Solaris Cluster, نسخة4
·
- Oracle SQL Developer, نسخ ما قبل 21.99
·
- Oracle StorageTek ACSLS, نسخة8.5.1
·
- Oracle StorageTek Tape Analytics (STA), نسخة2.4
·
- Oracle Taleo Platform, نسخ ما قبل 22.1
·
- Oracle Transportation Management, نسخ 6.4.3, 6.5.1
·
- Oracle Tuxedo, نسخة12.2.2.0.0
·
- Oracle Utilities Framework, نسخ 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0
·
- Oracle VM VirtualBox, نسخ ما قبل 6.1.34
·
- Oracle Web Services Manager, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle WebCenter Portal, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle WebCenter Sites, نسخ 12.2.1.3.0, 12.2.1.4.0
·
- Oracle WebLogic Server, نسخ 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
·
- Oracle ZFS Storage Appliance Kit, نسخة8.8
·
- OSS Support Tools, نسخ 2.12.42, 18.3
·
- PeopleSoft Enterprise CS Academic Advisement, نسخة9.2
·
- PeopleSoft Enterprise FIN Cash Management, نسخة9.2
·
- PeopleSoft Enterprise PeopleTools, نسخ 8.58, 8.59
·
- PeopleSoft Enterprise PRTL Interaction Hub, نسخة9.1
·
- Primavera Unifier, نسخ 17.7-17.12, 18.8, 19.12, 20.12, 21.12
·
يمكن للمهاجم استغلال الثغرات وتنفيذ أبرز ما يلي:
- تحديث أو وصول غير مصرح به أو إدراج أو حذف أو قراءة في بعض البرامج عن بعد وبدون صلاحيات
- التحكّم ببعض البرامج
- تنفيذ برمجيات خبيثة
- تجاوز سعة مخزن الذاكرة المؤقت
- الكشف عن المعلومات الحساسة
- أخطاء عند التحقق من المدخلات
يوصي المركز بتحديث المنتجات المتأثرة، حيث أصدرت Oracle توضيحًا لهذه التحديثات: