漏洞信息详情
Oracle Java SE和Oracle Java SE Embedded 安全漏洞
漏洞简介
Oracle Java SE和Oracle Java SE Embedded都是美国甲骨文(Oracle)公司的产品。Oracle Java SE是一款用于开发和部署桌面、服务器以及嵌入设备和实时环境中的Java应用程序。Oracle Java SE Embedded是一款针对嵌入式系统的、可移植的应用程序的Java平台。
Oracle Java SE和Oracle Java SE Embedded 存在安全漏洞,该漏洞源于通过未加密的LDAP连接发送凭据。以下产品及版本受到影响:Java SE: 7u271, 8u261, 11.0.8 , 15;Java SE Embedded: 8u261。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.oracle.com/security-alerts/cpuoct2020.html
参考网址
来源:DEBIAN
链接:https://www.debian.org/security/2020/dsa-4779
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00041.html
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/10/msg00031.html
来源:GENTOO
链接:https://security.gentoo.org/glsa/202101-19
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20201023-0004/
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2020.html
来源:www.nsfocus.net
链接:http://www.nsfocus.net/vulndb/50406
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0914
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-resilient-soar-is-using-components-with-known-vulnerabilities-java-se-cve-2020-14781/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4058/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Oracle-Java-OpenJDK-vulnerabilities-of-October-2020-33649
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3648/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-rational-directory-server-tivoli-rational-directory-administrator-6/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-has-announced-a-release-for-ibm-security-identity-governance-and-intelligence-in-response-to-a-security-vulnerability-cve-2020-14781/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159678/Red-Hat-Security-Advisory-2020-4307-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4454/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4389/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0797
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-has-announced-a-release-for-ibm-security-identity-governance-and-intelligence-in-response-to-a-security-vulnerability-cve-2020-14781-2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2930
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-affect-ibm-websphere-application-server-in-ibm-cloud-4/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4098/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-xstream-java-openssl-websphere-application-server-liberty-and-node-js-affect-ibm-spectrum-control/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-privileged-identity-manager-is-affected-by-sensitive-information-exposure-vulnerability-in-ibm-java-se-cve-2020-14781/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-march-2021-vulnerability-in-ibm-java-runtime-affects-cics-transaction-gateway/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-the-ibm-java-runtime-affect-ibm-rational-clearquest-2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerabilities-in-java-se-affects-rational-build-forge-3/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-deferred-from-oracle-oct-2020-cpu-for-java-8-cve-2020-14781-may-affect-ibm-sdk-java-technology-edition-and-ibm-operations-analytics-predictive-insig/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0562
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affects-websphere-application-server-october-2020-cpu-that-is-bundled-with-ibm-websphere-application-server-patterns/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6491175
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2140
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3664/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-is-vulnerable-to-multiple-issues-with-the-ibm-runtime-environment-java-technology-edition-shipped-with-ibm-mq-cve-2020-14781-cve-2020-14782/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6484395
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-security-bulletin-ibm-sdk-java-quarterly-cpu-oct-2020-vulnerabilities-affect-ibm-transformation-extender/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1139
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1216
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-z-tpf-5/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-java-runtime-affect-ibm-spectrum-conductor-and-ibm-spectrum-conductor-with-spark-3/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4201/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-cve-2020-14781-may-affect-ibm-sdk-java-technology-edition-for-content-collector-for-email-content-collector-for-file-systems-content-collector-for-microsoft-sharepoi/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160570/Red-Hat-Security-Advisory-2020-5586-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161088/Gentoo-Linux-Security-Advisory-202101-19.html
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2020.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3772.2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-cves-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-designer-used-in-ibm-business-automation-workflow-and-ibm-business-process-manager/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-security-directory-server-4/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159719/Red-Hat-Security-Advisory-2020-4348-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0773
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-tivoli-system-automation-for-multiplatforms-oct-2020-cpu-cve-2020-14781/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159744/Ubuntu-Security-Notice-USN-4607-1.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-may-affect-ibm-sdk-java-technology-edition-5/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affects-websphere-application-server-january-2021-cpu-that-is-bundled-with-ibm-websphere-application-server-patterns/
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2020-14781
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6518920
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-java-runtime-affects-ibm-messagegateway-cve-2020-14781/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-and-ibm-java-runtime-affect-rational-performance-tester-6/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerablities-in-ibm-sdk-java-technology-edition-quarterly/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-rational-directory-server-tivoli-rational-directory-administrator-8/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sdk-java-technology-edition-quarterly-cpu-oct-2020-and-jan-2021/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6487179
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160053/Ubuntu-Security-Notice-USN-4607-2.html
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6483057
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3929/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0811
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-ibm-java-sdk-affect-ibm-websphere-cast-iron-solution-app-connect-professional-4/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-oct-2020-patch-update-for-java/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161669/Red-Hat-Security-Advisory-2021-0736-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3694.2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0012/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3771/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0072/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-sdk-java-technology-edition-may-affect-ibm-cloud-orchestrator-and-ibm-cloud-orchestrator-enterprise/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-has-been-identified-in-ibm-sdk-java-technology-edition-shipped-with-ibm-tivoli-netcool-impact-cve-2020-14781/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-pak-for-automation-3/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4319.2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-ibm-sdk-java-technology-edition-version-7-version-8-that-is-used-by-ibm-workload-scheduler-2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-is-affected-by-a-java-se-vulnerability-cve-2020-14781/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-aix-5/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6486151
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-an-unspecified-vulnerability-in-java-se-results-in-a-low-confidentiality-impact/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-websphere-service-registry-and-repository-and-websphere-service-registry-and-repository-studio-january-2021-cpu/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-cve-2020-14781-may-affect-ibm-sdk-java-technology-edition-2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-os-images-for-red-hat-linux-systems-used-by-ibm-cloud-pak-system-jan2021-updates/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-in-ibm-java-sdk-affects-ibm-voice-gateway-4/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-an-unspecified-vulnerability-in-java-se-related-to-the-jndi-component-could-affect-infosphere-streams/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-14781
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161661/Red-Hat-Security-Advisory-2021-0717-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0061/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-ibm-java-runtime-affecting-tivoli-netcool-omnibus-multiple-cves-3/
受影响实体
暂无
补丁
- OpenJDK 安全漏洞的修复措施<!--2020-10-20-->
还没有评论,来说两句吧...