重庆思庄Oracle、Redhat认证学习论坛

标题: weblogic反序列化漏洞补丁 [打印本页]

作者: 郑全    时间: 2016-6-6 14:30
标题: weblogic反序列化漏洞补丁
Applies to:   Oracle Fusion Middleware
Oracle WebLogic Server - Version 10.3.6 to 12.2.1.0.0
Information in this document applies to any platform.
This applies to any product deployment using Oracle WebLogic Server


PurposeThis document defines minimum releases and patches for the Oracle WebLogic Server component of Oracle Fusion Middleware to address the vulnerability described in the Oracle Security Alert for CVE-2015-4852:  http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.html
DetailsIt is important to read the Oracle Security Alert before reading this document. The table below defines minimum releases and patches for Oracle WebLogic Server.


WLS ReleaseRequired Patches
12.2.1.012.2.1.0.0 Patch 22248372 for CVE-2015-4852
12.1.3.0PSU 12.1.3.0.5 (Patch 21370953) + 12.1.3.0.5 Patch 22248372 for CVE-2015-4852
12.1.2.0PSU 12.1.2.0.7 (Patch 21364493) + 12.1.2.0.7 Patch 22248372 for CVE-2015-4852
10.3.6.0PSU 10.3.6.0.12 (Patch 20780171), Smart Update Patch ID: EJUW) + 10.3.6.0.12 Patch 22248372 for CVE-2015-4852


ReferencesNOTE:2076338.1 - CVE-2015-4852 Mitigation Recommendations for Oracle WebLogic Server Component of Oracle Fusion Middleware
NOTE:1074055.1 - Security Vulnerability FAQ for Oracle Database and Fusion Middleware Products





欢迎光临 重庆思庄Oracle、Redhat认证学习论坛 (http://bbs.cqsztech.com/) Powered by Discuz! X3.2