¡¾Îó²îͨ¸æ¡¿Oracle Identity Manager Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2026-21992)
Ðû²¼Ê±¼ä 2026-04-08Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Oracle Identity Manager Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2026-21992 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2026-4-8 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Oracle Identity Manager ÊÇOracle Fusion MiddlewareϵͳÖеÄÉí·ÝÓë»á¼ûÖÎÀí×é¼þ£¬£¬£¬Ö÷ÒªÓÃÓÚÆóÒµÓû§Éí·ÝÉúÃüÖÜÆÚÖÎÀí¡¢È¨ÏÞ·ÖÅÉÓëºÏ¹æ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£Oracle Web Services ManagerÔòÓÃÓÚWebЧÀÍÇå¾²ÖÎÀíÓëÕ½ÂÔ¿ØÖÆ£¬£¬£¬Ö§³ÖЧÀÍÈÏÖ¤¡¢ÊÚȨ¡¢Éó¼ÆÓë¼ÓÃܵȹ¦Ð§£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶SOAºÍ΢ЧÀͼܹ¹ÇéÐÎÖС£¡£¡£¡£¡£¡£¡£
2026Äê4ÔÂ8ÈÕ£¬£¬£¬918²©ÌìÌÃÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Oracle Identity ManagerÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚOracle Identity ManagerºÍOracle Web Services ManagerÖУ¬£¬£¬ÓÉÓÚϵͳÔÚÔ¶³Ì½Ó¿Ú´¦Öóͷ£Àú³ÌÖÐȱ·¦ÓÐÓõÄÉí·ÝÈÏÖ¤ÓëÊäÈëУÑé»úÖÆ£¬£¬£¬µ¼ÖÂδÊÚȨ¹¥»÷Õß¿ÉÖ±½Óͨ¹ýÍøÂç½á¹¹¶ñÒâÇëÇó´¥·¢Îó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÎÞÐèµÇ¼¼´¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨ÏÞ£¬£¬£¬½øÒ»²½ÊµÑéºáÏòÉøÍ¸¡¢Êý¾ÝÇÔÈ¡»òЧÀÍÆÆËðµÈ¹¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¾ßÓÐʹÓÃÃż÷µÍ¡¢Ó°Ïì¹æÄ£¹ãµÄÌØµã£¬£¬£¬¿ÉÄܵ¼ÖÂÆóÒµÒªº¦ÓªÒµÏµÍ³Ê§¿Ø£¬£¬£¬²¢±£´æÎ¥·´Êý¾ÝÇå¾²¼°ºÏ¹æÒªÇó£¨ÈçÊý¾Ý±£»£»£»£»£»£»£»¤Óë»á¼û¿ØÖÆÒªÇ󣩵ÄΣº¦¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://www.oracle.com/security-alerts/alert-cve-2026-21992.html/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ