IBM API ConnectÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-05

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-4202£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬ £¬CVSS·ÖÖµ£º10

CVE±àºÅ£ºCVE-2019-4203£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾¼°²úÆ·


IBM API Connect 5.0.0.0°æ±¾ÖÁ5.0.8.6°æ±¾


Îó²î¸ÅÊö


IBM API Connect£¨APIConnect£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×ÓÃÓÚÖÎÀíAPIÉúÃüÖÜÆÚµÄ¼¯³É½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ö§³Ö½¨Éè¡¢ÔËÐС¢ÖÎÀíºÍ±£»£»£»£»£»£»£»£»¤APIºÍ΢ЧÀ͵È¡£¡£¡£¡£¡£¡£¡£¡£ÊÇÐí¶à½ðÈÚ»ú¹¹ÓÃÀ´Ö§³ÖPSD2»®¶¨µÄ¿ª·ÅÒøÐÐЧÀͲúÆ·¡£¡£¡£¡£¡£¡£¡£¡£


F-SecureÑо¿Ö°Ô±·¢Ã÷IBM API ConnectÖб£´æÁ½¸öÑÏÖØÎó²î£º


CVE-2019-4202

ÏÂÁî×¢ÈëÎó²î£¬£¬£¬ £¬¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬ £¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨ÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-4203

ÍâµØÎļþ°üÀ¨Îó²î£¬£¬£¬ £¬¹¥»÷Õ߿ɽèÖúDeveloper PortalʹÓøÃÎó²îÏÂÔØÖ÷»ú²Ù×÷ϵͳÉϵÄí§ÒâÎļþ²¢¿ÉÄÜʵÑéЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£º
https://www-01.ibm.com/support/docview.wss?uid=ibm10880109

https://www-01.ibm.com/support/docview.wss?uid=ibm10880569


²Î¿¼Á´½Ó


https://www-01.ibm.com/support/docview.wss?uid=ibm10880109
https://www-01.ibm.com/support/docview.wss?uid=ibm10880569