IBM QRadar SIEMÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4888£©
Ðû²¼Ê±¼ä 2021-02-030x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-4888 | ʱ ¼ä | 2021-02-03 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ |
0x01 Îó²îÏêÇé
IBM QRadar Security Information and Event Management (SIEM) ÊÇIBM¹«Ë¾µÄÒ»Ì×±»ÆÕ±éʹÓõÄÇå¾²ÖÇÄܱ£»£»£»£»£»£»¤×ʲúºÍÐÅÏ¢Ô¶Àë¸ß¼¶ÍþвµÄ½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£Ëü¿É×ÊÖúÇå¾²ÍŶÓ׼ȷ¼ì²âÆóÒµÖеÄÍþв²¢»®·ÖÓÅÏȼ¶£¬£¬£¬£¬£¬²¢ÇÒÄܹ»ÖÇÄܶ´²ì£¬£¬£¬£¬£¬×ÊÖúÍŶÓѸËÙ×ö³ö·´Ó¦£¬£¬£¬£¬£¬´Ó¶øïÔÌÊÂÎñÔì³ÉµÄÓ°Ïì¡£¡£¡£¡£¡£¡£
2021Äê01ÔÂ27ÈÕ£¬£¬£¬£¬£¬IBMÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬¹ûÕæÁËIBM QRadar SIEMÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4888£©£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£
ÓÉÓÚJava·´ÐòÁл¯¹¦Ð§¶ÔÓû§ÌṩµÄÄÚÈݾÙÐÐÁ˲»Çå¾²µÄ·´ÐòÁл¯£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâµÄÐòÁл¯Java¹¤¾ßÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬£¬µ«PoCÒÑÔÚGithubÉϹûÕæ¡£¡£¡£¡£¡£¡£
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬Í¨¹ýzoomeyeËÑË÷£¬£¬£¬£¬£¬È«Çò¹²ÂþÑÜ1262292¸ö×°±¸ºÍÍøÕ¾£¬£¬£¬£¬£¬ÆäÖÐÖйúÂþÑÜ123429£¬£¬£¬£¬£¬Î»¾ÓµÚÈý¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
IBM QRadar SIEM 7.4.0 - 7.4.2 Patch 1
IBM QRadar SIEM 7.3.0 -7.3.3 Patch 7
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÈçϰ汾£º
QRadar/QRM/QVM 7.4.2 Patch 2
ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.4.2-QRADAR-QRSIEM-20210120225428&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR
QRadar/QRM/QVM 7.3.3 Patch 7 IF 1
ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.3.3-QRADAR-QRSIEM-20210120163940INT&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR
0x03 ²Î¿¼Á´½Ó
https://www.ibm.com/support/pages/node/6409306
https://nvd.nist.gov/vuln/detail/CVE-2020-4888
https://gist.githubusercontent.com/testanull/e9ba06d0c0c403402f6941fe2dbb868a/raw/7c86ee239ce6edbc8b2f1b3b253196af946f6905/CVE-2020-4888_poc.txt
0x04 ʱ¼äÏß
2021-01-27 IBMÐû²¼Ç徲ͨ¸æ
2021-02-03 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/