¡¾Îó²îͨ¸æ¡¿IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î(CVE-2024-51450)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î

CVE   ID

CVE-2024-51450

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


IBM Security Verify DirectoryÊÇÒ»¿îÆóÒµ¼¶Éí·ÝºÍ»á¼ûÖÎÃ÷È·¾ö¼Æ»®£¬ÌṩÇå¾²µÄÓû§Éí·ÝÖÎÀíºÍĿ¼·þÎñ£¬Ö§³ÖÖØ´óµÄÈÏÖ¤ºÍÊÚȨÐèÇó£¬×ÊÖú×éÖ¯±£»¤Ãô¸ÐÊý¾Ý¡£IBM Security Verify Access ApplianceÊÇÒ»¿îÓÃÓÚÖÎÀíÆóÒµÓ¦ÓóÌÐò»á¼ûµÄ½â¾ö¼Æ»®£¬ÌṩÉí·ÝÑéÖ¤¡¢µ¥µãµÇ¼¡¢È¨ÏÞ¿ØÖƺͶàÒòËØÈÏÖ¤¹¦Ð§¡£Á½Õßͨ¹ý¼¯ÖÐÖÎÀíÓû§»á¼ûȨÏÞºÍÇå¾²Õ½ÂÔ£¬È·±£ÆóÒµÓ¦ÓõÄÇå¾²ÐÔÓëºÏ¹æÐÔ£¬ÆÕ±éÓ¦ÓÃÓÚÌáÉý×éÖ¯µÄÍøÂçÇå¾²ÐÔºÍÓû§ÖÎÀíЧÂÊ¡£


2025Äê2ÔÂ11ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½IBMÐû²¼Á˹ØÓÚCVE-2024-51450ºÍCVE-2024-49814Îó²îµÄÇ徲ͨ¸æ¡£IBMÇå¾²Ñé֤Ŀ¼£¨IBM Security Verify Directory£©ºÍÇå¾²ÑéÖ¤»á¼û×°±¸£¨IBM Security Verify Access Appliance£©±£´æÁ½¸öÑÏÖØÎó²î£¬¿ÉÄܱ»¹¥»÷ÕßʹÓ㬵¼ÖÂδÊÚȨ»á¼ûºÍÏÂÁîÖ´ÐС£CVE-2024-51450ÊÇÒ»¸öÔ¶³ÌÏÂÁî×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÈ«ÐĽṹµÄÇëÇó£¬ÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁCVSSÆÀ·ÖΪ9.1£¬Îó²î¼¶±ðÑÏÖØ¡£CVE-2024-49814ÊÇÒ»¸öÍâµØȨÏÞÌáÉýÎó²î£¬ÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý²»ÐëÒªµÄȨÏÞÖ´ÐвÙ×÷£¬´Ó¶ø»ñµÃ¸ü¸ßȨÏÞ£¬¿ÉÄÜÍêÈ«¿ØÖÆϵͳ£¬CVSSÆÀ·ÖΪ7.8£¬Îó²î¼¶±ð¸ßΣ¡£


¶þ¡¢Ó°Ïì¹æÄ£


10.0.0<=IBM Security Verify Directory<=10.0.3


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÂÔز¢×°ÖÃIBM Security Verify Directory°æ±¾10.0.3.1ÒÔ½â¾öÏà¹ØÇå¾²ÎÊÌâ¡£

ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/pages/ibm-security-verify-directory-fix-level-10031-download-document/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/7182558

https://nvd.nist.gov/vuln/detail/CVE-2024-51450
https://nvd.nist.gov/vuln/detail/CVE-2024-49814
https://securityonline.info/ibm-security-verify-directory-vulnerable-to-critical-security-flaw-cve-2024-51450-cvss-9-1/