CVE-2020-4464 | WebSphere Application ServerÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-230x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-4464 |
ʱ ¼ä |
2020-07-23 |
|
Àà ÐÍ |
RCE |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
WebSphere Application Server 9.0,8.5,8.0,7.0 |
0x01 ·ì϶ÏêÇé
2020Äê7ÔÂ16ÈÕ£¬IBM°ä²¼ÁËÒ»¸ö°²È«¸üУ¬½¨¸´ÁËÒ»¸öWebSphere Application ServerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4464£©¡£¸Ã·ì϶µ¼Ö¹¥»÷Õ߿ɻú¹ØÒ»¸ö¶ñÒâµÄÐòÁл¯¶ÔÏ󣬲¢Í¨¹ýSOAPÏÎ½ÓÆ÷À´Ö´ÐÐËÁÒâJAVA´úÂë¡£
0x02 ´ëÖý¨Òé
V9.0.0.0ÖÁ9.0.5.4£¬ÓÐÁ½ÖÖ½¨¸´¹æ»®£º
? ³§ÉÌÒѰ䲼²¹¶¡£¬²¹¶¡ÏÂÔØ£º
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=9.0.5.3-WS-WAS-IFPH26952&includeSupersedes=0
? Éý¼¶µ½9.0.5.5»ò¸ü¸ß°æ±¾£¨Ö¸±ê¿ÉÓÃÐÔΪ2020ÄêµÚÈý¼¾¶È£©¡£
V8.5.0.0ÖÁ8.5.5.17£¬ÓÐÁ½ÖÖ½¨¸´¹æ»®£º
? ³§ÉÌÒѰ䲼²¹¶¡£¬²¹¶¡ÏÂÔØ£º
http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.5.5.14-WS-WAS-IFPH26952&includeSupersedes=0
? Éý¼¶µ½8.5.5.18»ò¸ü¸ß°æ±¾£¨Ö¸±ê¿ÉÓÃÐÔΪ2020ÄêµÚÈý¼¾¶È£©¡£
V8.0.0.0ÖÁ8.0.0.15£º
? Éý¼¶µ½8.0.0.15£¬¶øºó²Î¿¼£º
http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.0.0.15-WS-WAS-IFPH26952&includeSupersedes=0
V7.0.0.0ÖÁ7.0.0.45£º
? Éý¼¶µ½7.0.0.45£¬¶øºó²Î¿¼£º
http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.45-WS-WAS-IFPH26952&includeSupersedes=0
°ÑÎÈ£ºWebSphere Application Server V7.0ºÍV8.0ÒѲ»ÔÙÊØ»¤¡£
0x03 ÓйØÐÂÎÅ
https://www.hkcert.org/my_url/en/alert/20072001
0x04 ²Î¿¼Á´½Ó
https://www.ibm.com/support/pages/node/6250059
0x05 ¹¦·òÏß
2020-07-23 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ