¡¾Ô­´´·ì϶¡¿WebSphere SSRF·ì϶¹«¸æ£¨CVE-2020-4365£©

°ä²¼¹¦·ò 2020-06-01

·ì϶¸ÅÊö


IBM ¹Ù·½°ä²¼µÄ×îв¹¶¡ÖÐÔ̺¬±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab·¢ÏÖ²¢µÚÒ»¹¦·òÌá½»¸ø¹Ù·½µÄ·ì϶ £¬·ì϶±àºÅΪCVE-2020-4365¡£Í¨¹ý¸Ã·ì϶ £¬Ô¶³Ì¹¥»÷Õ߿ɶÔÖ¸±ê½øÐÐSSRF¹¥»÷ÀûÓá£


·ì϶¹¦·òÖá


2020Äê3ÔÂ17ÈÕ £¬ADLab½«·ì϶ÏêÇéÌá½»¸øIBM¹Ù·½£»

2020Äê3ÔÂ25ÈÕ £¬IBM¹Ù·½È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·×ÅÊÖ½¨¸´£»

2020Äê5ÔÂ14ÈÕ £¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½³ÆÐ»¡£


ÊÜÓ°Ïì°æ±¾


WebSphere Application Server Version 8.5


·ì϶ÀûÓÃ


²âÊÔ»·¾³£º×°ÖÃÔÚWindows Server 2008Ï嵀 WebSphere 8.5


·ì϶ÀûÓóÉЧ£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¶ã±Ü¹æ»®


Éý¼¶×îв¹¶¡£º

https://www.ibm.com/support/pages/node/6209099



±¦ÔËÀ³¹Ù·½ÍøÕ¾»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Äê £¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖ¹Ä¿Ç° £¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶1000Óà¸ö £¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶800Óà¸ö £¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÒÆ¶¯ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑС£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾