IBM Spectrum Protect Plus¶à¸öÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-10Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-4210£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4213£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4222£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4212£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4211£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
IBM Spectrum Protect Plus 10.1.0-10.1.5
Îó²î¸ÅÊö
IBM Spectrum Protect PlusÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý±£»£»£»£»£»£»£»¤Æ½Ì¨¡£¡£¡£¡£¡£¸Ãƽ̨ΪÆóÒµÌṩ¼òµ¥¿ØÖƺÍÖÎÀíµã£¬£¬£¬£¬£¬£¬£¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐéÄâ¡¢ÎïÀíºÍÔÆÇéÐξÙÐб¸·ÝºÍ»Ö¸´¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬ZDI¹ûÕæÅû¶ÁËIBM Spectrum Protect Plus²úÆ·ÖеÄ5¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£ÕâЩÎó²î¶¼±£´æÓÚAdministrative Console Framework serviceÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÕâЩÎó²î¶¼ÎÞÐèÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º
CVE-2020-4210
Îó²îÔ´ÓÚÔÚ½«Óû§ÌṩµÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTPÏÂÁîʹÓøÃÎó²îÔÚÊÜÓ°ÏìµÄIBM Spectrum Protect PlusÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
CVE-2020-4213
Îó²îÔ´ÓÚÔÚÆÊÎöusername²ÎÊýµÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÖÎÀíÔ±µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
CVE-2020-4222
Îó²îÔ´ÓÚÔÚÆÊÎöpassword²ÎÊýʱ£¬£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄ×Ö·û´®¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£
CVE-2020-4212
Îó²îÔ´ÓÚÔÚÆÊÎöhfpackage²ÎÊýʱ£¬£¬£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
CVE-2020-4211
Îó²îÔ´ÓÚÔÚÆÊÎöhostname²ÎÊýʱ£¬£¬£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttp://www.ibm.com/support/docview.wss?uid=ibm11072392¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-20-270/
https://www.zerodayinitiative.com/advisories/ZDI-20-271/
https://www.zerodayinitiative.com/advisories/ZDI-20-272/
https://www.zerodayinitiative.com/advisories/ZDI-20-273/
https://www.zerodayinitiative.com/advisories/ZDI-20-274/