IBM DataRisk Manager |¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-23

0x00 ·ì϶¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

IBM Data Risk Manager

ÔÝÎÞ

AB

ÑϳÁ

ÊÇ

IBM Data Risk Manager 2.0.1 to 2.0.3

IBM Data Risk Manager 2.0.4 to 2.0.6 ¿ÉÄÜÊÜÓ°Ïì

ÔÝÎÞ

CI

ÑϳÁ

ÊÇ

ÔÝÎÞ

IDP

ÑϳÁ

ÊÇ

ÔÝÎÞ

AFD

¸ßΣ

ÊÇ


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


AgileÐÅÏ¢°²È«¹«Ë¾µÄ×êÑÐÈËÔ±Pedro Ribeiro 4ÔÂ21ÈÕÔÚGitHubÉϹ«¿ªÅû¶ÁËËĸöIBM 0day·ì϶¡£ÕâЩ·ì϶ӰÏìIBM DataRisk Manager£¨IDRM£©£¬IDRMÊÇÒ»¿îÆóÒµ°²È«¹¤¾ß£¬¾ÛºÏÀ´×Ô·ì϶ɨÃ蹤¾ßºÍÆäËû·çÏÕÖÎÀí¹¤¾ßµÄÐÅÏ¢£¬ÒÔ±ãÖÎÀíÔ±µ÷²é°²È«ÎÊÌâ¡£

ÔÚ·ÖÎöIDRM LinuxÐé¹¹É豸ʱ£¬Ribeiro·¢ÏÖÁË4¸ö0day£ºÉí·ÝÈÏÖ¤ÃýÎó·ì϶¡¢ºÅÁî×¢Èë·ì϶¡¢²»°²È«µÄĬÈÏÃÜÂë·ì϶ÒÔ¼°ËÁÒâÎļþÏÂÔØ·ì϶¡£ÕâЩ·ì϶Äܹ»µ¥¶ÀʹÓÃÒ²Äܹ»×éºÏʹÓã¬×éºÏʹÓÃǰÈý¸ö·ì϶Äܹ»Ê¹¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬×éºÏʹÓõÚÒ»¸öºÍµÚËĸö·ì϶Äܹ»Ê¹Î´ÊÚȨµÄ¹¥»÷ÕßÏÂÔØËÁÒâÎļþ¡£

·ì϶µÄÅû¶ÕßRibeiro°µÊ¾£¬IDRMÊÇ´¦ÖÃÃô¸ÐÐÅÏ¢µÄÆóÒµ°²È«²úÆ·£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑϳÁÊÜËð£¬Òò¶øÔÚIBM»Ø¾ø½ÓÊÜ·ì϶»ã±¨ºóÑ¡Ôñ½«Æä°ä²¼³öÀ´¡£Ä¿Ç°£¬IBM¹«Ë¾½¨¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄËÁÒâÎļþÏÂÔØ·ì϶ºÍºÅÁî×¢Èë·ì϶£¬²¢ÇÒÔÚµ÷²éÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£

£¨1£©Éí·ÝÈÏÖ¤ÃýÎó·ì϶ԴÓÚIDRMÔÚ/ albatross / saml / idpSelectionÓÐÒ»¸öAPI½«¹¥»÷ÕßÌṩµÄIDÓëϵͳÉϵÄÓÐЧÓû§ÓйØÁª¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶³ÁÖÃÈκÎÒÑÓÐÕË»§ÃÜÂ룬Ô̺¬ÖÎÀíÔ±ÃÜÂë¡£

£¨2£©ºÅÁî×¢Èë·ì϶ԴÓÚIDRMµÄ/albatross/restAPI/v2/nmap/run/scanÖеÄij¸öAPIÔÊÐíÓû§Ê¹ÓÃnmap¾ç±¾Ö´ÐÐÍøÂçɨÃ裬ÈôÊǸþ籾ÎļþÓɹ¥»÷ÕßÉÏ´«£¬ÄÇô¾Í¿ÉÄܱ»¸½¼Ó¶ñÒâºÅÁî¡£

£¨3£©Ä¬ÈÏÃÜÂë·ì϶²úÉúµÄÔ­ÒòÔÚÓÚIDRMÐé¹¹É豸ÖеÄÖÎÀíÓû§ÊÇ¡°a3user¡±£¬Ä¬ÈÏÃÜÂëΪ¡°idrm¡±¡£¸ÃÓû§±»ÔÊÐíͨ¹ýSSHµÇ¼ºÍÔËÐÐsudoºÅÁî¡£¹ÌÈ»IDRMÇ¿Ôìweb½Ó¿ÚµÄÖÎÀíÔ±Óû§£¨¡°admin¡±£©ÔÚ³õ´ÎµÇ¼ʱÅú¸ÄÃÜÂ룬µ«ÊÇȴûÓÐÒªÇó¡°a3user¡±Óû§Åú¸ÄÃÜÂë¡£

£¨4£©ËÁÒâÎļþÏÂÔØ·ì϶ԴÓÚ/albatross/eurekaservice/fetchLogFilesÖеÄij¸öAPIÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§´ÓϵͳÏÂÔØÈÕÖ¾Îļþ¡£µ«ÊÇ£¬logFileNameList²ÎÊýÔ̺¬Ò»¸öĿ¼±éÀú·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶´ÓϵͳÏÂÔØËÁÒâÎļþ¡£


0x02 ´ëÖý¨Òé


ºÅÁî×¢Èë·ì϶ºÍËÁÒâÎļþÏÂÔØ·ì϶Òѽ¨¸´£¬½«IDRMÉý¼¶µ½2.0.4°æ±¾¼´¿É¡£ÏÂÔØµØÖ·£ºhttps://www.ibm.com/software/passportadvantage/pacustomers.html£»

ĬÈÏÃÜÂë·ì϶£¬IBM½¨Ò鯾¾Ý°ä²¼µÄ×°ÖÃÖ¸ÄÏÔÚ³õ´Î×°ÖÃʱ³ÁÖᣲο¼Á´½Ó£ºhttps://www.ibm.com/support/knowledgecenter/en/SSJQ6V_2.0.6/com.ibm.idrm.doc/install/tsk/tsk_installguide_idrm_configuration.html£»

Éí·ÝÈÏÖ¤ÃýÎó·ì϶ÁÙʱûÓн¨¸´£¬Çëʵʱ¹Ø×¢³§ÉÌÐÅÏ¢£ºhttps://www.ibm.com/support/pages/node/6195705¡£


0x03 ÓйØÐÂÎÅ


https://www.zdnet.com/article/security-researcher-discloses-four-ibm-zero-days-after-company-refused-to-patch/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://github.com/pedrib/PoC/blob/master/advisories/IBM/ibm_drm/ibm_drm_rce.md


0x05 ¹¦·òÏß


2020-04-21 GitHub°ä²¼·ì϶

2020-04-23 VSRC°ä²¼·ì϶¹«¸æ



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾