WebSphere |Ô¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-14

0x00 Îó²î¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

WebSphere

CVE-2020-4276

´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

WebSphere Application Server 7.0¡¢8.0¡¢8.5¡¢9.0

WebSphere

CVE-2020-4362

´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

WebSphere Application Server 7.0¡¢8.0¡¢8.5¡¢9.0



0x01 Îó²îÏêÇé

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

IBM WebSphere Application Server£¨WAS£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»¿îÓ¦ÓÃЧÀÍÆ÷²úÆ·¡£ ¡£¡£¸Ã²úÆ·ÊÇÒ»ÖÖ¸ßÐÔÄܵÄJavaÖÐÐļþЧÀÍÆ÷£¬£¬£¬¿ÉÓÃÓÚ¹¹½¨¡¢ÔËÐС¢¼¯³É¡¢±£»£»£»¤ºÍÖÎÀíÄÚ²¿°²ÅźÍ/»òÍⲿ°²ÅŵĶ¯Ì¬ÔƺÍWebÓ¦Ó㬣¬£¬ËüÊÇÒ»ÖÖJavaEEºÍWebЧÀÍÓ¦ÓóÌÐòµÄƽ̨£¬£¬£¬Ò²ÊÇIBMWebSphereÈí¼þƽ̨µÄ»ù´¡¡£ ¡£¡£


ƾ֤IBM¹Ù·½Í¨¸æ£¬£¬£¬WebSphere Application ServerÔÚͨ¹ýSOAPÅþÁ¬Æ÷µÄÖÎÀíÇëÇóÖÐʹÓûùÓÚÁîÅÆµÄÉí·ÝÈÏ֤ʱ£¬£¬£¬±£´æÒ»´¦ÌØÈ¨ÌáÉýÎó²î£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ ¡£¡£WebSphere SOAP ConnectorЧÀÍÓÃÓÚÖÎÀíÔ¶³Ì½ÚµãºÍÊý¾Ýͬ²½£¬£¬£¬ÆäĬÈϼàÌý0.0.0.0:8880¶Ë¿Ú¡£ ¡£¡£

IBMÔÚ1Ô·ݽӵ½Îó²î±¨¸æºó£¬£¬£¬·ÖÅÉÁËÎó²î±àºÅCVE-2020-4276²¢ÓÚ3Ô·ÝÐû²¼²¹¶¡PH21511¡£ ¡£¡£Ñо¿Ö°Ô±Ëæºó·¢Ã÷¸Ã²¹¶¡²¢Î´ÐÞ¸´¸ÃÎó²î£¬£¬£¬IBMÔÚÈ·ÈϺóÔÙ´ÎÐû²¼²¹¶¡PH23853²¢ÇÒ·ÖÅÉÎó²î±àºÅCVE-2020-4362¡£ ¡£¡£Òò´ËÕâÁ½¸öCVE±àºÅÏÖʵÉÏÊÇͳһ¸öÎó²î¡£ ¡£¡£


0x02 ´¦Öóͷ£½¨Òé


? WebSphere Application Server V9.0.0.0µ½9.0.5.3£ºÉý¼¶ÖÁ9.0.5.4»òÓ¦Óò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V8.5.0.0µ½8.5.5.17£ºÉý¼¶ÖÁ8.5.5.18»òÓ¦Óò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V8.0.0.0µ½8.0.0.15£ºÉý¼¶ÖÁ8.0.0.15£¬£¬£¬È»ºóÓ¦Óò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V7.0.0.0µ½7.0.0.45£ºÉý¼¶ÖÁ7.0.0.45£¬£¬£¬È»ºóÓ¦Óò¹¶¡PH21511¼°PH23853


0x03 Ïà¹ØÐÂÎÅ


https://www.auscert.org.au/bulletins/ESB-2020.1064/


0x04 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/6118222

https://www.ibm.com/support/pages/node/6174417

https://nvd.nist.gov/vuln/detail/CVE-2020-4276

https://nvd.nist.gov/vuln/detail/CVE-2020-4362

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202003-1621


0x05 ʱ¼äÏß


2020-01-26  IBM½Óµ½Îó²î±¨¸æ

2020-03-25  ¹Ù·½·ÖÅÉÎó²î±àºÅCVE-2020-4276£¬£¬£¬Ðû²¼²¹¶¡PH21511

2020-04-09  ¹Ù·½È·ÈÏÎó²îÐÞ²¹²»µ±£¬£¬£¬ÔٴηÖÅÉÎó²î±àºÅCVE-2020-4362£¬£¬£¬Ðû²¼²¹¶¡PH23853

2020-04-13  Îó²îÐÅÏ¢¹ûÕæ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨