¡¾Ô­´´Îó²î¡¿WebSphereÎó²î£¨CVE-2019-4505£©

Ðû²¼Ê±¼ä 2019-09-20

0x01 Îó²îÐÎò


IBM ¹Ù·½Ðû²¼µÄWebsphere×îÐÂÇå¾²²¹¶¡ÖаüÀ¨ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÇå¾²Îó²î£¬Îó²î±àºÅΪCVE-2019-4505¡£Í¨¹ý¸ÃÎó²î£¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½Ê¹Ó᣸ÃÎó²îΣº¦½Ï´ó£¬½¨ÒéʵʱÉý¼¶×îÐÂÇå¾²²¹¶¡¡£


0x02 Îó²îʱ¼äÖá


2019Äê7ÔÂ19ÈÕ£¬ADLab½«Îó²îÏêÇéÌá½»¸øIBM¹Ù·½£»

2019Äê7ÔÂ30ÈÕ£¬IBM¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´£»

2019Äê9ÔÂ18ÈÕ£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½ÖÂл¡£


0x03 Ó°Ïì°æ±¾


WebSphere Application Server Version 9.0

WebSphere Application Server Version 8.5

WebSphere Application Server Version 8.0

WebSphere Application Server Version 7.0

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£


0x04 Îó²î¸´ÏÖ


²âÊÔÇéÐΣºWindows7 + WebSphere 8.5


Îó²î¸´ÏÖ£º


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢



0x05 ¹æ±Ü¼Æ»®


Éý¼¶²¹¶¡¡£IBM¹Ù·½¸üÐÂÁ´½ÓµØµã£ºhttps://www.ibm.com/support/pages/node/964766