¡¾Îó²îͨ¸æ¡¿Oracle E-Business Suite Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-61882)

Ðû²¼Ê±¼ä 2025-10-09

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Oracle E-Business Suite Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-61882

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2025-10-9

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

ÒÑ·¢Ã÷


Oracle E-Business Suite£¨EBS£©ÊÇÒ»¸ö×ÛºÏÐÔµÄÆóÒµ×ÊÔ´ÍýÏ루ERP£©Èí¼þÌ×¼þ£¬£¬£¬ £¬£¬£¬Ö¼ÔÚ×ÊÖúÆóÒµÖÎÀí²ÆÎñ¡¢¹©Ó¦Á´¡¢ÈËÁ¦×ÊÔ´¡¢¿Í»§¹ØÏµµÈÒªº¦ÓªÒµÁ÷³Ì¡£¡£¡£EBSÌṩÆÕ±éµÄÄ£¿£¿£¿ £¿£¿£¿é»¯Ó¦Ó㬣¬£¬ £¬£¬£¬°üÀ¨²ÆÎñÖÎÀí¡¢²É¹º¡¢ÖÆÔì¡¢¿â´æ¡¢ÏîÄ¿ÖÎÀíµÈ£¬£¬£¬ £¬£¬£¬Äܹ»Öª×ã²î±ð¹æÄ£ºÍÐÐÒµµÄÐèÇ󡣡£¡£×÷ΪOracleµÄÆì½¢²úÆ·£¬£¬£¬ £¬£¬£¬EBSÌṩ¸ß¶ÈµÄ¿É¶¨ÖÆÐԺͼ¯³ÉÄÜÁ¦£¬£¬£¬ £¬£¬£¬Ö§³ÖÈ«Çò»¯²Ù×÷£¬£¬£¬ £¬£¬£¬²¢Í¨¹ýÓëÆäËûOracleÊÖÒÕ¿ÍÕ»µÄÎ޷켯³É£¬£¬£¬ £¬£¬£¬×ÊÖúÆóÒµÌá¸ßЧÂÊ¡¢½µµÍ±¾Ç®¡¢ÓÅ»¯¾öÒé¡£¡£¡£


2025Äê10ÔÂ9ÈÕ£¬£¬£¬ £¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½Oracle E-Business SuiteÖеÄÒ»¸öÑÏÖØÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬±£´æÓÚÆäOracle Concurrent Processing×é¼þµÄBI Publisher¼¯ÀÖ³ÉÄÜÖС£¡£¡£¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýÍøÂçÔ¶³ÌÖ´ÐдúÂ룬£¬£¬ £¬£¬£¬¼´¹¥»÷ÕßÎÞÐèÓû§ÃûºÍÃÜÂë¼´¿ÉÌᳫ¹¥»÷¡£¡£¡£ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼Ö¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬ £¬£¬£¬´Ó¶øÊµÏÖÍêÈ«¿ØÖÆ£¬£¬£¬ £¬£¬£¬ÑÏÖØÍþвϵͳÇå¾²¡£¡£¡£Òѱ»¶à¸ö¹¥»÷ÕßʹÓ㬣¬£¬ £¬£¬£¬°üÀ¨ÀÕË÷Èí¼þÍŻ¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


12.2.3 <= Oracle E-Business Suite <= 12.2.14


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Oracle¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬£¬£¬ £¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://www.oracle.com/security-alerts/alert-cve-2025-61882.html/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£

ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.oracle.com/security-alerts/alert-cve-2025-61882.html/
https://nvd.nist.gov/vuln/detail/CVE-2025-61882