Oracle Critical Patch Update 보안 업데이트 권고

2022-10-19

□ 개요
 o 오라클社 CPU에서 자사 제품의 보안 취약점 370개에 대한 패치 발표 [1]
  ※ CPU(Critical Patch Update) : 오라클 중요 보안 업데이트
 o 영향받는 버전의 사용자는 악성코드 감염 등에 취약할 수 있으므로, 아래 해결 방안에 따라 최신 버전으로 업데이트 권고

□ 영향받는 제품 및 버전
영향받는 제품 패치 관련 문서
Oracle E-Business Suite
Data
Enterprise Manager
Enterprise Manager
Enterprise Manager
JD Edwards
JD Edwards
MySQL
MySQL
MySQL
MySQL
MySQL
MySQL
MySQL
Fusion Middleware
Oracle Supply Chain Products
Oracle Supply Chain Products
Oracle Airlines Data Model
Data
Oracle Supply Chain Products
Oracle Supply Chain Products
Oracle Banking Platform
Contact Support
Oracle Banking Platform
Oracle Banking Platform
Oracle Analytics
Fusion Middleware
Oracle Analytics
Fusion Middleware
Fusion Middleware
Oracle Commerce
Oracle Communications Billing and Revenue Management
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Converged Application Server - Service Controller
Oracle Communications Convergence
Oracle Communications Convergent Charging Controller
Oracle Communications Data Model
Oracle Communications Design Studio
Oracle Communications Diameter Signaling Router
Oracle Communications Element Manager
Oracle Communications Evolved Communications Application Server
Oracle Communications Instant Messaging Server
Oracle Communications Interactive Session Recorder
Oracle Communications Messaging Server
Oracle Communications MetaSolv Solution
Oracle Communications Network Charging and Control
Oracle Communications Order and Service Management
Oracle Communications Policy Management
Oracle Communications Pricing Design Center
Oracle Communications Services Gatekeeper
Oracle Communications Session Border Controller
Oracle Communications Session Report Manager
Oracle Communications Unified Assurance
Oracle Communications User Data Repository
Oracle Communications WebRTC Session Controller
Fusion Middleware
Data
Oracle Insurance Applications
Oracle E-Business Suite
Fusion Middleware
Oracle Enterprise Operations Monitor
Data
Oracle Financial Services Analytical Applications Infrastructure
Oracle Financial Services Behavior Detection Platform
Oracle Financial Services Enterprise Case Management
Oracle Financial Services Model Management and Governance
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Data
Java SE
HealthCare Applications
HealthCare Applications
HealthCare Applications
HealthCare Applications
Oracle Hospitality Cruise Fleet Management
Oracle Hospitality Cruise Shipboard Property Management System
Oracle Hospitality Suite8
Fusion Middleware
Oracle Enterprise Performance Management
Fusion Middleware
Oracle Insurance Applications
Java SE
Fusion Middleware
Fusion Middleware
NoSQL Data
Fusion Middleware
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Retail Applications
Oracle SD-WAN Aware
Oracle SD-WAN Edge
Oracle Secure Backup
Fusion Middleware
Systems
Systems
Data
Data
Oracle Supply Chain Products
Oracle Utilities Applications
Virtualization
Fusion Middleware
Fusion Middleware
Fusion Middleware
Fusion Middleware
PeopleSoft
PeopleSoft
Oracle Construction and Engineering Suite
Oracle Construction and Engineering Suite
Siebel

□ 해결 방안
 o "Oracle Critical Patch Update Advisory - October 2022“ 문서 및 패치 사항을 검토하고 벤더 사 및 유지보수 업체와 협의/검토 후 패치 적용 [1]
 o JAVA SE 사용자는 설치된 제품의 최신 업데이트를 다운로드[2] 받아 설치하거나, Java 업데이트 자동 알림 설정을 권고 [3]

□ 기타 문의사항
 o 한국인터넷진흥원 사이버민원센터: 국번없이 118

[참고사이트]
[1] https://www.oracle.com/security-alerts/cpuoct2022.html
[2] http://www.oracle.com/technetwork/java/javase/downloads/index.html
[3] https://www.java.com/ko/download/help/java_update.html


□ 작성 : 침해사고분석단 취약점분석팀