WebSphere |Ô¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-14

0x00 Îó²î¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Ó°Ïì¹æÄ£

WebSphere

CVE-2020-4276

´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

WebSphere Application Server 7.0¡¢8.0¡¢8.5¡¢9.0

WebSphere

CVE-2020-4362

´úÂëÖ´ÐÐ

¸ßΣ

ÊÇ

WebSphere Application Server 7.0¡¢8.0¡¢8.5¡¢9.0



0x01 Îó²îÏêÇé

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

IBM WebSphere Application Server£¨WAS£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»¿îÓ¦ÓÃЧÀÍÆ÷²úÆ·¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·ÊÇÒ»ÖÖ¸ßÐÔÄܵÄJavaÖÐÐļþЧÀÍÆ÷ £¬£¬ £¬¿ÉÓÃÓÚ¹¹½¨¡¢ÔËÐС¢¼¯³É¡¢± £»£»£»£»¤ºÍÖÎÀíÄÚ²¿°²ÅźÍ/»òÍⲿ°²ÅŵĶ¯Ì¬ÔƺÍWebÓ¦Óà £¬£¬ £¬ËüÊÇÒ»ÖÖJavaEEºÍWebЧÀÍÓ¦ÓóÌÐòµÄƽ̨ £¬£¬ £¬Ò²ÊÇIBMWebSphereÈí¼þƽ̨µÄ»ù´¡¡£¡£¡£¡£¡£¡£¡£¡£


ƾ֤IBM¹Ù·½Í¨¸æ £¬£¬ £¬WebSphere Application ServerÔÚͨ¹ýSOAPÅþÁ¬Æ÷µÄÖÎÀíÇëÇóÖÐʹÓûùÓÚÁîÅÆµÄÉí·ÝÈÏ֤ʱ £¬£¬ £¬±£´æÒ»´¦ÌØÈ¨ÌáÉýÎó²î £¬£¬ £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£WebSphere SOAP ConnectorЧÀÍÓÃÓÚÖÎÀíÔ¶³Ì½ÚµãºÍÊý¾Ýͬ²½ £¬£¬ £¬ÆäĬÈϼàÌý0.0.0.0:8880¶Ë¿Ú¡£¡£¡£¡£¡£¡£¡£¡£

IBMÔÚ1Ô·ݽӵ½Îó²î±¨¸æºó £¬£¬ £¬·ÖÅÉÁËÎó²î±àºÅCVE-2020-4276²¢ÓÚ3Ô·ÝÐû²¼²¹¶¡PH21511¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ëæºó·¢Ã÷¸Ã²¹¶¡²¢Î´ÐÞ¸´¸ÃÎó²î £¬£¬ £¬IBMÔÚÈ·ÈϺóÔÙ´ÎÐû²¼²¹¶¡PH23853²¢ÇÒ·ÖÅÉÎó²î±àºÅCVE-2020-4362¡£¡£¡£¡£¡£¡£¡£¡£Òò´ËÕâÁ½¸öCVE±àºÅÏÖʵÉÏÊÇͳһ¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


? WebSphere Application Server V9.0.0.0µ½9.0.5.3£ºÉý¼¶ÖÁ9.0.5.4»òÓ¦Óò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V8.5.0.0µ½8.5.5.17£ºÉý¼¶ÖÁ8.5.5.18»òÓ¦Óò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V8.0.0.0µ½8.0.0.15£ºÉý¼¶ÖÁ8.0.0.15 £¬£¬ £¬È»ºóÓ¦Óò¹¶¡PH21511¼°PH23853

? WebSphere Application Server V7.0.0.0µ½7.0.0.45£ºÉý¼¶ÖÁ7.0.0.45 £¬£¬ £¬È»ºóÓ¦Óò¹¶¡PH21511¼°PH23853


0x03 Ïà¹ØÐÂÎÅ


https://www.auscert.org.au/bulletins/ESB-2020.1064/


0x04 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/6118222

https://www.ibm.com/support/pages/node/6174417

https://nvd.nist.gov/vuln/detail/CVE-2020-4276

https://nvd.nist.gov/vuln/detail/CVE-2020-4362

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202003-1621


0x05 ʱ¼äÏß


2020-01-26  IBM½Óµ½Îó²î±¨¸æ

2020-03-25  ¹Ù·½·ÖÅÉÎó²î±àºÅCVE-2020-4276 £¬£¬ £¬Ðû²¼²¹¶¡PH21511

2020-04-09  ¹Ù·½È·ÈÏÎó²îÐÞ²¹²»µ± £¬£¬ £¬ÔٴηÖÅÉÎó²î±àºÅCVE-2020-4362 £¬£¬ £¬Ðû²¼²¹¶¡PH23853

2020-04-13  Îó²îÐÅÏ¢¹ûÕæ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾