¡¾Ô­´´Â©¶´¡¿WebSphere SSRF©¶´Í¨¸æ£¨CVE-2020-4365£©

Ðû²¼Ê±¼ä 2020-06-01

©¶´¸ÅÊö


IBM ¹Ù·½Ðû²¼µÄ×îв¹¶¡ÖаüÂÞ¶«É­Æ½Ì¨ADLab·¢ÏÖ²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄ©¶´£¬Â©¶´±àºÅΪCVE-2020-4365¡£Í¨¹ý¸Ã©¶´£¬Ô¶³Ì¹¥»÷Õ߿ɶÔÄ¿±ê½øÐÐSSRF¹¥»÷ÀûÓá£


©¶´Ê±¼äÖá


2020Äê3ÔÂ17ÈÕ£¬ADLab½«Â©¶´ÏêÇéÌá½»¸øIBM¹Ù·½£»

2020Äê3ÔÂ25ÈÕ£¬IBM¹Ù·½È·ÈÏ©¶´´æÔÚ²¢¿ªÊ¼×ÅÊÖÐÞ¸´£»

2020Äê5ÔÂ14ÈÕ£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½ÖÂл¡£


ÊÜÓ°Ïì°æ±¾


WebSphere Application Server Version 8.5


©¶´ÀûÓÃ


²âÊÔ»·¾³£º°²×°ÔÚWindows Server 2008Ï嵀 WebSphere 8.5


©¶´ÀûÓÃЧ¹û£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹æ±Ü·½°¸


Éý¼¶×îв¹¶¡£º

https://www.ibm.com/support/pages/node/6209099



¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´800Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾