IBM Spectrum Protect Plus¶à¸öÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-10Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-4210£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4213£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4222£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4212£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2020-4211£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
IBM Spectrum Protect Plus 10.1.0-10.1.5
Îó²î¸ÅÊö
IBM Spectrum Protect PlusÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý±£»£»£»£»£»£»¤Æ½Ì¨¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨ΪÆóÒµÌṩ¼òµ¥¿ØÖƺÍÖÎÀíµã£¬£¬£¬£¬£¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐéÄâ¡¢ÎïÀíºÍÔÆÇéÐξÙÐб¸·ÝºÍ»Ö¸´¡£¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬ZDI¹ûÕæÅû¶ÁËIBM Spectrum Protect Plus²úÆ·ÖеÄ5¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¶¼±£´æÓÚAdministrative Console Framework serviceÖУ¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÕâЩÎó²î¶¼ÎÞÐèÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º
CVE-2020-4210
Îó²îÔ´ÓÚÔÚ½«Óû§ÌṩµÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTPÏÂÁîʹÓøÃÎó²îÔÚÊÜÓ°ÏìµÄIBM Spectrum Protect PlusÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-4213
Îó²îÔ´ÓÚÔÚÆÊÎöusername²ÎÊýµÄʱ¼ä£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÖÎÀíÔ±µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-4222
Îó²îÔ´ÓÚÔÚÆÊÎöpassword²ÎÊýʱ£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄ×Ö·û´®¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-4212
Îó²îÔ´ÓÚÔÚÆÊÎöhfpackage²ÎÊýʱ£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
CVE-2020-4211
Îó²îÔ´ÓÚÔÚÆÊÎöhostname²ÎÊýʱ£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Îó²î£¬£¬£¬£¬£¬Á´½Ó£ºhttp://www.ibm.com/support/docview.wss?uid=ibm11072392¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zerodayinitiative.com/advisories/ZDI-20-270/
https://www.zerodayinitiative.com/advisories/ZDI-20-271/
https://www.zerodayinitiative.com/advisories/ZDI-20-272/
https://www.zerodayinitiative.com/advisories/ZDI-20-273/
https://www.zerodayinitiative.com/advisories/ZDI-20-274/


¾©¹«Íø°²±¸11010802024551ºÅ