¡¾Ô´´Îó²î¡¿WebSphere SSRFÎó²îͨ¸æ£¨CVE-2020-4365£©
Ðû²¼Ê±¼ä 2020-06-01Îó²î¸ÅÊö
IBM ¹Ù·½Ðû²¼µÄ×îв¹¶¡ÖаüÀ¨ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÎó²î£¬Îó²î±àºÅΪCVE-2020-4365¡£Í¨¹ý¸ÃÎó²î£¬Ô¶³Ì¹¥»÷Õ߿ɶÔÄ¿µÄ¾ÙÐÐSSRF¹¥»÷ʹÓá£
Îó²îʱ¼äÖá
2020Äê3ÔÂ17ÈÕ£¬ADLab½«Îó²îÏêÇéÌá½»¸øIBM¹Ù·½£»
2020Äê3ÔÂ25ÈÕ£¬IBM¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´£»
2020Äê5ÔÂ14ÈÕ£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½ÖÂл¡£
ÊÜÓ°Ïì°æ±¾
WebSphere Application Server Version 8.5
Îó²îʹÓÃ
²âÊÔÇéÐΣº×°ÖÃÔÚWindows Server 2008Ï嵀 WebSphere 8.5
Îó²îʹÓÃЧ¹û£º
¹æ±Ü¼Æ»®
Éý¼¶×îв¹¶¡£º
https://www.ibm.com/support/pages/node/6209099
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î800Óà¸ö£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØϵͳÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£