IBM QRadar SIEMÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4888£©
°ä²¼¹¦·ò 2021-02-030x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-4888 | ʱ ¼ä | 2021-02-03 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé

IBM QRadar Security Information and Event Management (SIEM) ÊÇIBM¹«Ë¾µÄÒ»Ì×±»¿í·ºÊ¹ÓõݲȫÖÇÄܱ£»¤×ʲúºÍÐÅÏ¢Ô¶Àë¸ß¼¶ÍþвµÄ½â¾ö¹æ»®¡£Ëü¿ÉÔ®ÊÖ°²È«ÍŶÓÕýÈ·¼ì²âÆóÒµÖеÄÍþв²¢»®·ÖÓÅÏȼ¶£¬²¢ÇÒ¿ÉÄÜÖÇÄܶ´²ì£¬Ô®ÊÖÍŶÓѸ¿ì×ö³ö·´Ó³£¬´Ó¶øÏ÷¼õÊÂÎñÔì³ÉµÄÓ°Ïì¡£
2021Äê01ÔÂ27ÈÕ£¬IBM°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËIBM QRadar SIEMÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4888£©£¬ÆäCVSSv3ÆÀ·Ö8.8¡£
ÓÉÓÚJava·´ÐòÁл¯Ö°ÄܶÔÓû§ÌṩµÄÄÚÈݽøÐÐÁ˲»°²È«µÄ·´ÐòÁл¯£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâµÄÐòÁл¯Java¶ÔÏóÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâºÅÁĿǰ¸Ã·ì϶Òѱ»½¨¸´£¬µ«PoCÒÑÔÚGithubÉϹ«¿ª¡£
½ØÖ¹Ä¿Ç°£¬Í¨¹ýzoomeyeËÑË÷£¬È«Çò¹²É¢²¼1262292¸öÉ豸ºÍÍøÕ¾£¬ÆäÖÐÖйúÉ¢²¼123429£¬Î»¾ÓµÚÈý¡£

Ó°ÏìÁìÓò
IBM QRadar SIEM 7.4.0 - 7.4.2 Patch 1
IBM QRadar SIEM 7.3.0 -7.3.3 Patch 7
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬½¨ÒéÉý¼¶ÖÁÈçϰ汾£º
QRadar/QRM/QVM 7.4.2 Patch 2
ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.4.2-QRADAR-QRSIEM-20210120225428&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR
QRadar/QRM/QVM 7.3.3 Patch 7 IF 1
ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.3.3-QRADAR-QRSIEM-20210120163940INT&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR
0x03 ²Î¿¼Á´½Ó
https://www.ibm.com/support/pages/node/6409306
https://nvd.nist.gov/vuln/detail/CVE-2020-4888
https://gist.githubusercontent.com/testanull/e9ba06d0c0c403402f6941fe2dbb868a/raw/7c86ee239ce6edbc8b2f1b3b253196af946f6905/CVE-2020-4888_poc.txt
0x04 ¹¦·òÏß
2021-01-27 IBM°ä²¼°²È«²¼¸æ
2021-02-03 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ