IBM QRadar SIEMÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4888£©

Ðû²¼Ê±¼ä 2021-02-03

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2020-4888

ʱ  ¼ä

2021-02-03

Àà   ÐÍ

RCE

µÈ  ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

 

IBM QRadar Security Information and Event Management (SIEM) ÊÇIBM¹«Ë¾µÄÒ»Ì×±»ÆÕ±éʹÓõÄÇå¾²ÖÇÄܱ£» £»£» £»£»£»¤×ʲúºÍÐÅÏ¢Ô¶Àë¸ß¼¶ÍþвµÄ½â¾ö¼Æ»®¡£¡£ ¡£¡£¡£¡£Ëü¿É×ÊÖúÇå¾²ÍŶÓ׼ȷ¼ì²âÆóÒµÖеÄÍþв²¢»®·ÖÓÅÏȼ¶£¬ £¬£¬£¬ £¬²¢ÇÒÄܹ»ÖÇÄܶ´²ì£¬ £¬£¬£¬ £¬×ÊÖúÍŶÓѸËÙ×ö³ö·´Ó¦£¬ £¬£¬£¬ £¬´Ó¶øïÔÌ­ÊÂÎñÔì³ÉµÄÓ°Ïì¡£¡£ ¡£¡£¡£¡£

2021Äê01ÔÂ27ÈÕ£¬ £¬£¬£¬ £¬IBMÐû²¼Ç徲ͨ¸æ£¬ £¬£¬£¬ £¬¹ûÕæÁËIBM QRadar SIEMÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4888£©£¬ £¬£¬£¬ £¬ÆäCVSSv3ÆÀ·Ö8.8¡£¡£ ¡£¡£¡£¡£

ÓÉÓÚJava·´ÐòÁл¯¹¦Ð§¶ÔÓû§ÌṩµÄÄÚÈݾÙÐÐÁ˲»Çå¾²µÄ·´ÐòÁл¯£¬ £¬£¬£¬ £¬µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâµÄÐòÁл¯Java¹¤¾ßÀ´Ê¹ÓôËÎó²î£¬ £¬£¬£¬ £¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬ £¬£¬£¬ £¬µ«PoCÒÑÔÚGithubÉϹûÕæ¡£¡£ ¡£¡£¡£¡£

×èÖ¹ÏÖÔÚ£¬ £¬£¬£¬ £¬Í¨¹ýzoomeyeËÑË÷£¬ £¬£¬£¬ £¬È«Çò¹²ÂþÑÜ1262292¸ö×°±¸ºÍÍøÕ¾£¬ £¬£¬£¬ £¬ÆäÖÐÖйúÂþÑÜ123429£¬ £¬£¬£¬ £¬Î»¾ÓµÚÈý¡£¡£ ¡£¡£¡£¡£

image.png

 

Ó°Ïì¹æÄ£

IBM QRadar SIEM 7.4.0 - 7.4.2 Patch 1

IBM QRadar SIEM 7.3.0 -7.3.3 Patch 7

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬ £¬£¬£¬ £¬½¨ÒéÉý¼¶ÖÁÈçϰ汾£º

QRadar/QRM/QVM 7.4.2 Patch 2

ÏÂÔØÁ´½Ó£º

https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.4.2-QRADAR-QRSIEM-20210120225428&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR

 

QRadar/QRM/QVM 7.3.3 Patch 7 IF 1

ÏÂÔØÁ´½Ó£º

https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.3.3-QRADAR-QRSIEM-20210120163940INT&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR

 

 

0x03 ²Î¿¼Á´½Ó

https://www.ibm.com/support/pages/node/6409306

https://nvd.nist.gov/vuln/detail/CVE-2020-4888

https://gist.githubusercontent.com/testanull/e9ba06d0c0c403402f6941fe2dbb868a/raw/7c86ee239ce6edbc8b2f1b3b253196af946f6905/CVE-2020-4888_poc.txt


0x04 ʱ¼äÏß

2021-01-27  IBMÐû²¼Ç徲ͨ¸æ

2021-02-03  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png