¡¾·ì϶¹«¸æ¡¿Oracle Scripting iSurveyÄ£¿£¿£¿éÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-30727)
°ä²¼¹¦·ò 2025-04-16Ò»¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Oracle Scripting iSurveyÄ£¿£¿£¿éÔ¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-30727 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-04-16 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Oracle ScriptingÊÇOracle E-Business SuiteÖеÄÒ»¸ö×é¼þ£¬£¬ÓÃÓÚ´´½¨ºÍÖÎÀíÔÚÏßµ÷²é¡¢±íµ¥¼°¶¯Ì¬¾ç±¾¡£ËüÔÊÐíÆóҵͨ¹ý¿É¶¨ÖÆµÄ¾ç±¾ÍøÂçÓû§Êý¾Ý£¬£¬Ö§³ÖÒµÎñÁ÷³Ì×Ô¶¯»¯ºÍ¾ö²ßÖ§³Ö¡£Oracle ScriptingÌṩÁ˽ýݵÄÎʾíÉè¼Æ¹¤¾ß£¬£¬¿ÉÄÜÓëÆäËûE-Business SuiteÄ£¿£¿£¿é¼¯³É£¬£¬ÊµÏÖÊý¾ÝµÄ×Ô¶¯»¯ÍøÂçÓë´¦Ö᣸ÃÄ£¿£¿£¿é¿í·ºÀûÓÃÓÚ¿Í»§µ÷²é¡¢·´À¡ÍøÂç¡¢ºÏ¹æÐÔÆÀ¹ÀµÈ³¡¾°¡£
2025Äê4ÔÂ16ÈÕ£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Oracle°ä²¼µÄCVE-2025-30727°²È«²¼¸æ¡£²¼¸æÖ¸³ö£¬£¬Oracle E-Business Suite µÄ Oracle Scripting ²úÆ·£¨×é¼þ£º£ºiSurvey Module£©´æÔÚÒ»ÏîÑÏÖØ·ì϶£¬£¬Î´ÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýHTTPÍøÂç½Ó¼ûÔ¶³ÌÀûÓø÷ì϶£¬£¬¿ÉÄܵ¼ÖÂOracle ScriptingÔâµ½½ÚÖÆ¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷¿ÉÄܵ¼ÖÂOracle Scripting±»ÆëÈ«¹¥Ï¡£·ì϶ÆÀ·Ö9.8·Ö£¬£¬·ì϶¼¶±ðΪÑÏÖØ¡£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º£ºhttps://www.oracle.com/security-alerts/cpuapr2025.html/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ