¡¾Ô­´´Â©¶´¡¿WebSphere©¶´£¨CVE-2019-4505£©

Ðû²¼Ê±¼ä 2019-09-20

0x01 ©¶´ÃèÊö


IBM ¹Ù·½Ðû²¼µÄWebsphere×îÐÂÄþ¾²²¹¶¡ÖаüÂÞ¶«É­Æ½Ì¨ADLab·¢ÏÖ²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÄþ¾²Â©¶´£¬Â©¶´±àºÅΪCVE-2019-4505¡£Í¨¹ý¸Ã©¶´£¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½ÀûÓ᣸鶴Σº¦½Ï´ó£¬½¨Ò鼰ʱÉý¼¶×îÐÂÄþ¾²²¹¶¡¡£


0x02 ©¶´Ê±¼äÖá


2019Äê7ÔÂ19ÈÕ£¬ADLab½«Â©¶´ÏêÇéÌá½»¸øIBM¹Ù·½£»

2019Äê7ÔÂ30ÈÕ£¬IBM¹Ù·½È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼×ÅÊÖÐÞ¸´£»

2019Äê9ÔÂ18ÈÕ£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½ÖÂл¡£


0x03 Ó°Ïì°æ±¾


WebSphere Application Server Version 9.0

WebSphere Application Server Version 8.5

WebSphere Application Server Version 8.0

WebSphere Application Server Version 7.0

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£


0x04 ©¶´¸´ÏÖ


²âÊÔ»·¾³£ºWindows7 + WebSphere 8.5


©¶´¸´ÏÖ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



0x05 ¹æ±Ü·½°¸


Éý¼¶²¹¶¡¡£IBM¹Ù·½¸üÐÂÁ´½ÓµØÖ·£ºhttps://www.ibm.com/support/pages/node/964766