¡¾Ô­´´Îó²î¡¿WebSphereÎó²î£¨CVE-2019-4505£©

Ðû²¼Ê±¼ä 2019-09-20

0x01 Îó²îÐÎò


IBM ¹Ù·½Ðû²¼µÄWebsphere×îÐÂÇå¾²²¹¶¡ÖаüÀ¨¼øºÚµ£±£ÍøADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÇå¾²Îó²î£¬£¬£¬£¬Îó²î±àºÅΪCVE-2019-4505¡£¡£¡£¡£Í¨¹ý¸ÃÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½Ê¹Óᣡ£¡£¡£¸ÃÎó²îΣº¦½Ï´ó£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶×îÐÂÇå¾²²¹¶¡¡£¡£¡£¡£


0x02 Îó²îʱ¼äÖá


2019Äê7ÔÂ19ÈÕ£¬£¬£¬£¬ADLab½«Îó²îÏêÇéÌá½»¸øIBM¹Ù·½ £»£»£»£»£»£»

2019Äê7ÔÂ30ÈÕ£¬£¬£¬£¬IBM¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´ £»£»£»£»£»£»

2019Äê9ÔÂ18ÈÕ£¬£¬£¬£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½ÖÂл¡£¡£¡£¡£


0x03 Ó°Ïì°æ±¾


WebSphere Application Server Version 9.0

WebSphere Application Server Version 8.5

WebSphere Application Server Version 8.0

WebSphere Application Server Version 7.0

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£¡£¡£¡£


0x04 Îó²î¸´ÏÖ


²âÊÔÇéÐΣºWindows7 + WebSphere 8.5


Îó²î¸´ÏÖ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



0x05 ¹æ±Ü¼Æ»®


Éý¼¶²¹¶¡¡£¡£¡£¡£IBM¹Ù·½¸üÐÂÁ´½ÓµØµã£ºhttps://www.ibm.com/support/pages/node/964766