CVE-2020-4464 | WebSphere Application ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-07-23

0x00 Îó²î¸ÅÊö



CVE   ID

CVE-2020-4464

ʱ    ¼ä

2020-07-23

Àà   ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

WebSphere Application Server 9.0,8.5,8.0,7.0


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2020Äê7ÔÂ16ÈÕ£¬£¬£¬IBMÐû²¼ÁËÒ»¸öÇå¾²¸üУ¬£¬£¬ÐÞ¸´ÁËÒ»¸öWebSphere Application ServerÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4464£©¡£ ¡£¡£¡£¡£¸ÃÎó²îµ¼Ö¹¥»÷Õ߿ɽṹһ¸ö¶ñÒâµÄÐòÁл¯¹¤¾ß£¬£¬£¬²¢Í¨¹ýSOAPÅþÁ¬Æ÷À´Ö´ÐÐí§ÒâJAVA´úÂë¡£ ¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


V9.0.0.0ÖÁ9.0.5.4£¬£¬£¬ÓÐÁ½ÖÖÐÞ¸´¼Æ»®£º

? ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬²¹¶¡ÏÂÔØ£º

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=9.0.5.3-WS-WAS-IFPH26952&includeSupersedes=0

? Éý¼¶µ½9.0.5.5»ò¸ü¸ß°æ±¾£¨Ä¿µÄ¿ÉÓÃÐÔΪ2020ÄêµÚÈý¼¾¶È£©¡£ ¡£¡£¡£¡£

V8.5.0.0ÖÁ8.5.5.17£¬£¬£¬ÓÐÁ½ÖÖÐÞ¸´¼Æ»®£º

? ³§ÉÌÒÑÐû²¼²¹¶¡£¬£¬£¬²¹¶¡ÏÂÔØ£º

http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.5.5.14-WS-WAS-IFPH26952&includeSupersedes=0

? Éý¼¶µ½8.5.5.18»ò¸ü¸ß°æ±¾£¨Ä¿µÄ¿ÉÓÃÐÔΪ2020ÄêµÚÈý¼¾¶È£©¡£ ¡£¡£¡£¡£

V8.0.0.0ÖÁ8.0.0.15£º

? Éý¼¶µ½8.0.0.15£¬£¬£¬È»ºó²Î¿¼£º

http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.0.0.15-WS-WAS-IFPH26952&includeSupersedes=0

V7.0.0.0ÖÁ7.0.0.45£º

? Éý¼¶µ½7.0.0.45£¬£¬£¬È»ºó²Î¿¼£º

http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.45-WS-WAS-IFPH26952&includeSupersedes=0

×¢ÖØ£ºWebSphere Application Server V7.0ºÍV8.0ÒѲ»ÔÙά»¤¡£ ¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.hkcert.org/my_url/en/alert/20072001


0x04 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/6250059


0x05 ʱ¼äÏß


2020-07-23 VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨