IBM API ConnectÑϳÁ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-05-05

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-4202 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º10

CVE±àºÅ£ºCVE-2019-4203 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾¼°²úÆ·


IBM API Connect 5.0.0.0°æ±¾ÖÁ5.0.8.6°æ±¾


·ì϶¸ÅÊö


IBM API Connect£¨APIConnect£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×ÓÃÓÚÖÎÀíAPIÐÔÃüÖÜÆÚµÄ¼¯³É½â¾ö¹æ»®¡£¸Ã²úÆ·Ö§³Ö´´½¨¡¢ÔËÐÓ×¢ÖÎÀíºÍ±£»¤APIºÍ΢·þÎñµÈ¡£ÊǺܶà½ðÈÚ»ú¹¹ÓÃÀ´Ö§³ÖPSD2»®¶¨µÄÊ¢¿ªÒøÐзþÎñ²úÆ·¡£


F-Secure×êÑÐÈËÔ±·¢ÏÖIBM API ConnectÖдæÔÚÁ½¸öÑϳÁ·ì϶£º


CVE-2019-4202

ºÅÁî×¢Èë·ì϶ £¬¸Ã·ì϶ԴÓÚ±í²¿ÊäÈëÊý¾Ý»ú¹Ø¿ÉÖ´ÐкÅÁî¹ý³ÌÖÐ £¬ÍøÂçϵͳ»ò²úƷδÕýÈ·¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨ºÅÁî¡£


CVE-2019-4203

±¾µØÎļþÔ̺¬·ì϶ £¬¹¥»÷Õ߿ɽèÖúDeveloper PortalÀûÓø÷ì϶ÏÂÔØÖ÷»ú²Ù×÷ϵͳÉϵÄËÁÒâÎļþ²¢¿ÉÄÜÖ´ÐзþÎñÆ÷¶ËÒªÇóαÔì¹¥»÷¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£º
https://www-01.ibm.com/support/docview.wss?uid=ibm10880109

https://www-01.ibm.com/support/docview.wss?uid=ibm10880569


²Î¿¼Á´½Ó


https://www-01.ibm.com/support/docview.wss?uid=ibm10880109
https://www-01.ibm.com/support/docview.wss?uid=ibm10880569