WebSphere |Ô¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-14

0x00 ·ì϶¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

WebSphere

CVE-2020-4276

´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

WebSphere Application Server 7.0¡¢8.0¡¢8.5¡¢9.0

WebSphere

CVE-2020-4362

´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

WebSphere Application Server 7.0¡¢8.0¡¢8.5¡¢9.0



0x01 ·ì϶ÏêÇé

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

IBM WebSphere Application Server£¨WAS£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»¿îÀûÓ÷þÎñÆ÷²úÆ· ¡£¸Ã²úÆ·ÊÇÒ»Öָ߻úÄܵÄJavaÖÐÑë¼þ·þÎñÆ÷£¬¿ÉÓÃÓÚ¹¹½¨¡¢ÔËÐÓ×¢¼¯³É¡¢±£»¤ºÍÖÎÀíÄÚ²¿²¿ÊðºÍ/»ò±í²¿²¿ÊðµÄ¶¯Ì¬ÔƺÍWebÀûÓã¬ËüÊÇÒ»ÖÖJavaEEºÍWeb·þÎñÀûÓ÷¨Ê½µÄƽ̨£¬Ò²ÊÇIBMWebSphereÈí¼þƽ̨µÄ»ù´¡ ¡£


ƾ¾ÝIBM¹Ù·½¹«¸æ£¬WebSphere Application ServerÔÚͨ¹ýSOAPÏÎ½ÓÆ÷µÄÖÎÀíÒªÇóÖÐʹÓûùÓÚÁîÅÆµÄÉí·ÝÈÏ֤ʱ£¬´æÔÚÒ»´¦ÌØÈ¨ÌáÉý·ì϶£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£WebSphere SOAP Connector·þÎñÓÃÓÚÖÎÀíÔ¶³Ì½ÚµãºÍÊý¾Ýͬ²½£¬ÆäĬÈϼàÌý0.0.0.0:8880¶Ë¿Ú ¡£

IBMÔÚ1Ô·ݽӵ½·ì϶»ã±¨ºó£¬·ÖÅäÁË·ì϶±àºÅCVE-2020-4276²¢ÓÚ3Ô·ݰ䲼²¹¶¡PH21511 ¡£×êÑÐÈËÔ±Ëæºó·¢Ïָò¹¶¡²¢Î´½¨¸´¸Ã·ì϶£¬IBMÔÚÈ·ÈϺóÔٴΰ䲼²¹¶¡PH23853²¢ÇÒ·ÖÅä·ì϶±àºÅCVE-2020-4362 ¡£Òò¶øÕâÁ½¸öCVE±àºÅÏÖʵÉÏÊÇͳһ¸ö·ì϶ ¡£


0x02 ´ëÖý¨Òé


? WebSphere Application Server V9.0.0.0µ½9.0.5.3£ºÉý¼¶ÖÁ9.0.5.4»òÀûÓò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V8.5.0.0µ½8.5.5.17£ºÉý¼¶ÖÁ8.5.5.18»òÀûÓò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V8.0.0.0µ½8.0.0.15£ºÉý¼¶ÖÁ8.0.0.15£¬¶øºóÀûÓò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V7.0.0.0µ½7.0.0.45£ºÉý¼¶ÖÁ7.0.0.45£¬¶øºóÀûÓò¹¶¡PH21511¼°PH23853


0x03 ÓйØÐÂÎÅ


https://www.auscert.org.au/bulletins/ESB-2020.1064/


0x04 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/6118222

https://www.ibm.com/support/pages/node/6174417

https://nvd.nist.gov/vuln/detail/CVE-2020-4276

https://nvd.nist.gov/vuln/detail/CVE-2020-4362

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202003-1621


0x05 ¹¦·òÏß


2020-01-26  IBM½Óµ½·ì϶»ã±¨

2020-03-25  ¹Ù·½·ÖÅä·ì϶±àºÅCVE-2020-4276£¬°ä²¼²¹¶¡PH21511

2020-04-09  ¹Ù·½È·ÈÏ·ì϶½¨²¹²»µ±£¬ÔٴηÖÅä·ì϶±àºÅCVE-2020-4362£¬°ä²¼²¹¶¡PH23853

2020-04-13  ·ì϶ÐÅÏ¢¹«¿ª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾