¡¾Ô­´´·ì϶¡¿WebSphere SSRF·ì϶¹«¸æ£¨CVE-2020-4365£©

°ä²¼¹¦·ò 2020-06-01

·ì϶¸ÅÊö


IBM ¹Ù·½°ä²¼µÄ×îв¹¶¡ÖÐÔ̺¬OG¶«·½ÌüADLab·¢ÏÖ²¢µÚÒ»¹¦·òÌá½»¸ø¹Ù·½µÄ·ì϶£¬£¬·ì϶±àºÅΪCVE-2020-4365¡£¡£¡£¡£Í¨¹ý¸Ã·ì϶£¬£¬Ô¶³Ì¹¥»÷Õ߿ɶÔÖ¸±ê½øÐÐSSRF¹¥»÷ÀûÓᣡ£¡£¡£


·ì϶¹¦·òÖá


2020Äê3ÔÂ17ÈÕ£¬£¬ADLab½«·ì϶ÏêÇéÌá½»¸øIBM¹Ù·½£»

2020Äê3ÔÂ25ÈÕ£¬£¬IBM¹Ù·½È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·×ÅÊÖÐÞ¸´£»

2020Äê5ÔÂ14ÈÕ£¬£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½³ÆÐ»¡£¡£¡£¡£


ÊÜÓ°Ïì°æ±¾


WebSphere Application Server Version 8.5


·ì϶ÀûÓÃ


²âÊÔ»·¾³£º×°ÖÃÔÚWindows Server 2008Ï嵀 WebSphere 8.5


·ì϶ÀûÓóÉЧ£º


OG¶«·½Ìü¡¤(Öйú´ó½)


¶ã±Ü¹æ»®


Éý¼¶×îв¹¶¡£¡£¡£¡£º

https://www.ibm.com/support/pages/node/6209099



OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£¡£¡£½ØÖ¹Ä¿Ç°£¬£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶1000Óà¸ö£¬£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶800Óà¸ö£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑС¢¡¢Òƶ¯ÖÇÄÜÖն˰²È«×êÑС¢¡¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑС¢¡¢Web°²È«×êÑС¢¡¢¹¤¿ØÏµÍ³°²È«×êÑС¢¡¢Ôư²È«×êÑС£¡£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£¡£


OG¶«·½Ìü¡¤(Öйú´ó½)