IBM QRadar SIEMÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4888£©

°ä²¼¹¦·ò 2021-02-03

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-4888

ʱ  ¼ä

2021-02-03

Àà   ÐÍ

RCE

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

 

IBM QRadar Security Information and Event Management (SIEM) ÊÇIBM¹«Ë¾µÄÒ»Ì×±»¿í·ºÊ¹ÓõݲȫÖÇÄܱ £»¤×ʲúºÍÐÅÏ¢Ô¶Àë¸ß¼¶ÍþвµÄ½â¾ö¹æ»®¡£Ëü¿ÉÔ®ÊÖ°²È«ÍŶÓÕýÈ·¼ì²âÆóÒµÖеÄÍþв²¢»®·ÖÓÅÏȼ¶£¬²¢ÇÒ¿ÉÄÜÖÇÄܶ´²ì£¬Ô®ÊÖÍŶÓѸ¿ì×ö³ö·´Ó³£¬´Ó¶øÏ÷¼õÊÂÎñÔì³ÉµÄÓ°Ïì¡£

2021Äê01ÔÂ27ÈÕ£¬IBM°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËIBM QRadar SIEMÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4888£©£¬ÆäCVSSv3ÆÀ·Ö8.8¡£

ÓÉÓÚJava·´ÐòÁл¯Ö°ÄܶÔÓû§ÌṩµÄÄÚÈݽøÐÐÁ˲»°²È«µÄ·´ÐòÁл¯£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâµÄÐòÁл¯Java¶ÔÏóÀ´ÀûÓô˷ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâºÅÁĿǰ¸Ã·ì϶Òѱ»½¨¸´£¬µ«PoCÒÑÔÚGithubÉϹ«¿ª¡£

½ØÖ¹Ä¿Ç°£¬Í¨¹ýzoomeyeËÑË÷£¬È«Çò¹²É¢²¼1262292¸öÉ豸ºÍÍøÕ¾£¬ÆäÖÐÖйúÉ¢²¼123429£¬Î»¾ÓµÚÈý¡£

image.png

 

Ó°ÏìÁìÓò

IBM QRadar SIEM 7.4.0 - 7.4.2 Patch 1

IBM QRadar SIEM 7.3.0 -7.3.3 Patch 7

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬½¨ÒéÉý¼¶ÖÁÈçϰ汾£º

QRadar/QRM/QVM 7.4.2 Patch 2

ÏÂÔØÁ´½Ó£º

https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.4.2-QRADAR-QRSIEM-20210120225428&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR

 

QRadar/QRM/QVM 7.3.3 Patch 7 IF 1

ÏÂÔØÁ´½Ó£º

https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.3.3-QRADAR-QRSIEM-20210120163940INT&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR

 

 

0x03 ²Î¿¼Á´½Ó

https://www.ibm.com/support/pages/node/6409306

https://nvd.nist.gov/vuln/detail/CVE-2020-4888

https://gist.githubusercontent.com/testanull/e9ba06d0c0c403402f6941fe2dbb868a/raw/7c86ee239ce6edbc8b2f1b3b253196af946f6905/CVE-2020-4888_poc.txt


0x04 ¹¦·òÏß

2021-01-27  IBM°ä²¼°²È«²¼¸æ

2021-02-03  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png