2017-10-19
▷ 개요
l
오라클社 CPU에서 자사 제품의 보안취약점 252개에 대한 패치를 발표 [1]
(CPU(Critical
Patch Update) : 오라클 중요 보안 업데이트)
l
영향 받는 버전의 사용자는 악성코드 감염에 취약할 수 있으므로, 아래
해결방안에 따라 최신버전으로 업데이트 권고
▷ 영향 받는 제품 및 버전
l
Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2,
M12-2S Servers, versions prior to XCP2340 and prior to XCP3030
l
Java Advanced Management Console, version 2.7
l
JD Edwards EnterpriseOne Tools, version 9.2
l
JD Edwards World Security, versions A9.1,
A9.2, A9.3, A9.4
l
Management Pack for Oracle GoldenGate,
version 11.2.1.0.12
l
MICROS Retail XBRi Loss Prevention, versions
10.0.1, 10.5.0, 10.6.0, 10.7.7, 10.8.0, 10.8.1
l
MySQL Connectors, versions 6.9.9 and prior
l
MySQL Enterprise Monitor, versions 3.2.8.2223
and prior, 3.3.4.3247 and prior, 3.4.2.4181 and prior
l
MySQL Server, versions 5.5.57 and prior,
5.6.37 and prior, 5.7.19 and prior
l
Oracle Access Manager, version 11.1.2.3.0
l
Oracle Agile Engineering Data Management,
versions 6.1.3, 6.2.0
l
Oracle Agile PLM, versions 9.3.5, 9.3.6
l
Oracle API Gateway, version 11.1.2.4.0
l
Oracle BI Publisher, versions 11.1.1.7.0,
11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0
l
Oracle Business Intelligence Enterprise
Edition, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0
l
Oracle Business Process Management Suite,
versions 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0
l
Oracle Communications Billing and Revenue
Management, version 7.5
l
Oracle Communications Diameter Signaling
Router (DSR), version 7.x
l
Oracle Communications EAGLE LNP Application
Processor, version 10.x
l
Oracle Communications Messaging Server,
version 8.x
l
Oracle Communications Order and Service
Management, versions 7.2.4.x.x, 7.3.0.x.x, 7.3.1.x.x, 7.3.5.x.x
l
Oracle Communications Policy Management,
versions 11.5, 12.x
l
Oracle Communications Services Gatekeeper,
versions 5.1, 6.0
l
Oracle Communications Unified Session
Manager, version SCz 7.x
l
Oracle Communications User Data Repository,
version 10.x
l
Oracle Communications WebRTC Session
Controller, versions 7.0, 7.1, 7.2
l
Oracle Database Server, versions 11.2.0.4,
12.1.0.2, 12.2.0.1
l
Oracle Directory Server Enterprise Edition,
version 11.1.1.7.0
l
Oracle E-Business Suite, versions 12.1.1,
12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7
l
Oracle Endeca Information Discovery
Integrator, versions 2.4, 3.0, 3.1, 3.2
l
Oracle Engineering Data Management, versions
6.1.3.0, 6.2.2.0
l
Oracle Enterprise Manager Ops Center,
versions 12.2.2, 12.3.2
l
Oracle FLEXCUBE Universal Banking, versions
11.3, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0
l
Oracle Fusion Applications, versions 11.1.2
through 11.1.9
l
Oracle Fusion Middleware, versions 11.1.1.7,
11.1.1.9, 11.1.2.2, 11.1.2.3, 12.1.3.0, 12.2.1.1, 12.2.1.2, 12.2.1.3
l
Oracle GlassFish Server, versions 3.0.1,
3.1.2
l
Oracle Healthcare Master Person Index,
version 4.x
l
Oracle Hospitality Cruise AffairWhere,
versions 2.2.5.0, 2.2.6.0, 2.2.7.0
l
Oracle Hospitality Cruise Fleet Management,
version 9.0.2.0
l
Oracle Hospitality Cruise Materials Management,
version 7.30.564.0
l
Oracle Hospitality Cruise Shipboard Property
Management System, version 8.0.2.0
l
Oracle Hospitality Guest Access, versions
4.2.0, 4.2.1
l
Oracle Hospitality Hotel Mobile, version 1.1
l
Oracle Hospitality OPERA 5 Property Services,
versions 5.4.2.x through 5.5.1.x
l
Oracle Hospitality Reporting and Analytics,
versions 8.5.1, 9.0.0
l
Oracle Hospitality Simphony, versions 2.6,
2.7, 2.8, 2.9
l
Oracle Hospitality Suite8, versions 8.10.1,
8.10.2
l
Oracle HTTP Server, versions 11.1.1.7.0,
11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0
l
Oracle Hyperion BI+, version 11.1.2.4
l
Oracle Hyperion Financial Reporting, version
11.1.2
l
Oracle Identity Manager, version 11.1.2.3.0
l
Oracle Identity Manager Connector, version
9.1.1.5.0
l
Oracle Integrated Lights Out Manager (ILOM),
versions prior to 3.2.6
l
Oracle iPlanet Web Server, version 7.0
l
Oracle Java SE, versions 6u161, 7u151, 8u144,
9
l
Oracle Java SE Embedded, version 8u144
l
Oracle JDeveloper, versions 12.1.3.0.0,
12.2.1.2.0
l
Oracle JRockit, version R28.3.15
l
Oracle Managed File Transfer, versions
12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0
l
Oracle Outside In Technology, version 8.5.3.0
l
Oracle Retail Back Office, versions 13.2,
13.3, 13.4, 14.0, 14.1
l
Oracle Retail Clearance Optimization Engine,
version 13.4
l
Oracle Retail Convenience and Fuel POS
Software, version 2.1.132
l
Oracle Retail Markdown Optimization, versions
13.4, 14.0
l
Oracle Retail Point-of-Service, versions
6.0.x, 6.5.x, 7.0.x, 7.1.x, 15.0.x, 16.0.0
l
Oracle Retail Store Inventory Management,
versions 13.2.9, 14.0.4, 14.1.3, 15.0.1, 16.0.1
l
Oracle Retail Xstore Point of Service,
versions 6.0.11, 6.5.11, 7.0.6, 7.1.6, 15.0.1
l
Oracle Secure Global Desktop (SGD), version
5.3
l
Oracle SOA Suite, version 11.1.1.7.0
l
Oracle Transportation Management, versions
6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.1, 6.4.2
l
Oracle Virtual Directory, versions
11.1.1.7.0, 11.1.1.9.0
l
Oracle VM VirtualBox, versions prior to
5.1.30
l
Oracle WebCenter Content, versions
11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0
l
Oracle WebCenter Sites, versions 11.1.1.8.0,
12.2.1.2.0
l
Oracle WebLogic Server, versions 10.3.6.0.0,
12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0
l
PeopleSoft Enterprise FSCM, version 9.2
l
PeopleSoft Enterprise HCM, version 9.2
l
PeopleSoft Enterprise PeopleTools, versions
8.54, 8.55, 8.56
l
PeopleSoft Enterprise PRTL Interaction Hub,
version 9.1.00
l
PeopleSoft Enterprise PT PeopleTools,
versions 8.54, 8.55, 8.56
l
PeopleSoft Enterprise SCM eProcurement,
versions 9.1.00, 9.2.00
l
Primavera Unifier, versions 9.13, 9.14, 10.x,
15.x, 16.x
l
Siebel Applications, versions 16.0, 17.0
l
Solaris Cluster, versions 3.3, 4.3
l
SPARC Enterprise M3000, M4000, M5000, M8000,
M9000 Servers, versions prior to XCP 1123
l
SPARC M7, T7, S7 based Servers, versions
prior to 9.7.6.b
l
Sun ZFS Storage Appliance Kit (AK), version
AK 2013
l
Tekelec HLR Router, version 4.x
▷ 해결 방안
l
"Oracle Critical Patch Update Advisory -
July 2017“
문서 및 패치사항을 검토하고 벤더사 및 유지보수 업체와 협의/검토 후 패치 적용[1]
l
JAVA SE 사용자는 설치된 제품의 최신 업데이트를 다운로드[2]
받아 설치하거나, Java 업데이트 자동 알림 설정을 권고[3]
▷ 참고 자료
- [1]http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- [2]
http://www.oracle.com/technetwork/java/javase/downloads/index.html
- [3] http://www.java.com/ko/download/help/java_update.xml