¡¾Ô´´Â©¶´¡¿WebSphere SSRF©¶´Í¨¸æ£¨CVE-2020-4365£©
Ðû²¼Ê±¼ä 2020-06-01©¶´¸ÅÊö
IBM ¹Ù·½Ðû²¼µÄ×îв¹¶¡ÖаüÂÞ¶«Éƽ̨ADLab·¢ÏÖ²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄ©¶´£¬Â©¶´±àºÅΪCVE-2020-4365¡£Í¨¹ý¸Ã©¶´£¬Ô¶³Ì¹¥»÷Õ߿ɶÔÄ¿±ê½øÐÐSSRF¹¥»÷ÀûÓá£
©¶´Ê±¼äÖá
2020Äê3ÔÂ17ÈÕ£¬ADLab½«Â©¶´ÏêÇéÌá½»¸øIBM¹Ù·½£»
2020Äê3ÔÂ25ÈÕ£¬IBM¹Ù·½È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼×ÅÊÖÐÞ¸´£»
2020Äê5ÔÂ14ÈÕ£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½ÖÂл¡£
ÊÜÓ°Ïì°æ±¾
WebSphere Application Server Version 8.5
©¶´ÀûÓÃ
²âÊÔ»·¾³£º°²×°ÔÚWindows Server 2008Ï嵀 WebSphere 8.5
©¶´ÀûÓÃЧ¹û£º
¹æ±Ü·½°¸
Éý¼¶×îв¹¶¡£º
https://www.ibm.com/support/pages/node/6209099
¶«Éƽ̨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´800Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£