內容說明

Oracle釋出115年6月安全性更新,共修補244個漏洞,其中包含159個高風險安全漏洞。 本篇整理重點為 CVE-2026-35273。其中至少一項漏洞已被提及遭利用,校內若有使用相關平台,應優先盤點與修補。


影響平台

  • APM-Application Performance Management 13.5與24.1版本
  • Identity Manager 12.2.1.4.0與14.1.2.1.0版本
  • Identity Manager Connector 12.2.1.4.0與14.1.2.1.0版本
  • JD Edwards EnterpriseOne Accounts Payable 9.2版本
  • JD Edwards EnterpriseOne General Ledger 9.2版本
  • JD Edwards EnterpriseOne Human Resources Management 9.2版本
  • JD Edwards EnterpriseOne Order Promising 9.2版本
  • JD Edwards EnterpriseOne Project Costing 9.2版本
  • JD Edwards EnterpriseOne Tools 9.2.0.0至9.2.26.2版本
  • MySQL Cluster 8.0.11至8.0.4版本
  • MySQL Cluster 8.4.0至8.4.9版本
  • MySQL Cluster 9.0.0至9.7.0版本
  • MySQL NDB Cluster 8.0.11至8.0.46版本
  • MySQL NDB Cluster 8.4.0至8.4.9版本
  • MySQL NDB Cluster 9.0.0至9.7.0版本
  • MySQL Router 8.4.0至8.4.9版本
  • MySQL Router 9.0.0至9.7.0版本
  • MySQL Server 8.4.0至8.4.9版本
  • MySQL Server 9.0.0至9.7.0版本
  • MySQL Shell 8.4.0至8.4.9版本
  • MySQL Shell 9.0.0至9.7.0版本
  • MySQL Shell 2026.2.0+9.6.1版本
  • Oracle Access Manager 12.2.1.4.0與14.1.2.1.0版本
  • Oracle Agile PLM 9.3.6版本
  • Oracle Application Development Framework (ADF) 12.2.1.4.0與14.1.2.0.0版本
  • Oracle Coherence 12.2.1.4.0、14.1.1.0.0、14.1.2.0.0及15.1.1.0.0版本
  • Oracle Communications Convergent Charging Controller 15.0.0.0.0、15.0.1.0.0、15.1.0.0.0及15.2.0.0.0版本
  • Oracle Communications Network Charging and Control 15.0.0.0.0、15.0.1.0.0、15.1.0.0.0及15.2.0.0.0版本
  • Oracle Communications Network Integrity 7.3.6、7.4.0、7.5.0及8.0.0版本
  • Oracle Data Integrator 12.2.1.4.0與14.1.2.0.0版本
  • Oracle E-Business Suite 12.2.3至12.2.15、V15及V16版本
  • Oracle Enterprise Manager Base Platform 13.5與24.1版本
  • Oracle Solaris 11.4版本
  • Oracle Unified Directory 12.2.1.4.0與14.1.2.1.0版本
  • Oracle Virtual Directory 12.2.1.4.0與14.1.2.0.0版本
  • Oracle VM VirtualBox 7.2.8版本
  • Oracle WebCenter Content 12.2.1.4.0與14.1.2.0.0版本
  • Oracle WebCenter Enterprise Capture 12.2.1.4.0與14.1.2.0.0版本
  • Oracle WebCenter Portal 12.2.1.4.0與14.1.2.0.0版本
  • Oracle WebCenter Sites 12.2.1.4.0與14.1.2.0.0版本
  • PeopleSoft Enterprise CS Campus Community 9.2.38版本
  • PeopleSoft Enterprise CS Student Financials 9.2.38版本
  • PeopleSoft Enterprise PT PeopleTools 8.61與8.62版本
  • Siebel Applications 17.0至26.5版本
  • WebCenter Content: Imaging 12.2.1.4.0與14.1.2.0.0版本
  • WebLogic Server 12.2.1.4.0、14.1.1.0.0、14.1.2.0.0及15.1.1.0.0版本

處置建議

  • 盤點校內是否使用受影響版本,包含自管、委外代管與專案環境。
  • 依官方或廠商公告套用修補版本;若短期無法更新,先限制管理介面來源並強化監控。
  • 檢查近期管理帳號登入、設定異動、異常腳本或未知管理操作紀錄。

CVE編號

CVE-2026-35273


參考資料