IBM API ConnectÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-05

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-4202£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º10

CVE±àºÅ£ºCVE-2019-4203£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾¼°²úÆ·


IBM API Connect 5.0.0.0°æ±¾ÖÁ5.0.8.6°æ±¾


Îó²î¸ÅÊö


IBM API Connect£¨APIConnect£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×ÓÃÓÚÖÎÀíAPIÉúÃüÖÜÆÚµÄ¼¯³É½â¾ö¼Æ»®¡£¡£¡£¸Ã²úÆ·Ö§³Ö½¨Éè¡¢ÔËÐС¢ÖÎÀíºÍ±£»£»£»£»£»£»£»¤APIºÍ΢ЧÀ͵È¡£¡£¡£ÊÇÐí¶à½ðÈÚ»ú¹¹ÓÃÀ´Ö§³ÖPSD2»®¶¨µÄ¿ª·ÅÒøÐÐЧÀͲúÆ·¡£¡£¡£


F-SecureÑо¿Ö°Ô±·¢Ã÷IBM API ConnectÖб£´æÁ½¸öÑÏÖØÎó²î£º


CVE-2019-4202

ÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬£¬£¬£¬£¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨ÏÂÁî¡£¡£¡£


CVE-2019-4203

ÍâµØÎļþ°üÀ¨Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽèÖúDeveloper PortalʹÓøÃÎó²îÏÂÔØÖ÷»ú²Ù×÷ϵͳÉϵÄí§ÒâÎļþ²¢¿ÉÄÜʵÑéЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£º
https://www-01.ibm.com/support/docview.wss?uid=ibm10880109

https://www-01.ibm.com/support/docview.wss?uid=ibm10880569


²Î¿¼Á´½Ó


https://www-01.ibm.com/support/docview.wss?uid=ibm10880109
https://www-01.ibm.com/support/docview.wss?uid=ibm10880569