¡¾Â©¶´Í¨¸æ¡¿IBM Security Verify DirectoryÃüÁîÖ´ÐЩ¶´(CVE-2024-51450)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Â©¶´¸ÅÊö


©¶´Ãû³Æ

IBM Security Verify DirectoryÃüÁîÖ´ÐЩ¶´

CVE   ID

CVE-2024-51450

©¶´ÀàÐÍ

ÃüÁîÖ´ÐÐ

·¢ÏÖʱ¼ä

2025-02-11

©¶´ÆÀ·Ö

9.1

©¶´Æ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


IBM Security Verify DirectoryÊÇÒ»¿îÆóÒµ¼¶Éí·ÝºÍ·ÃÎʹÜÀí½â¾ö·½°¸£¬ÌṩÄþ¾²µÄÓû§Éí·Ý¹ÜÀíºÍĿ¼·þÎñ£¬Ö§³ÖÅÓ´óµÄÈÏÖ¤ºÍÊÚȨÐèÇó£¬×ÊÖú×éÖ¯± £»¤Ãô¸ÐÊý¾Ý¡£IBM Security Verify Access ApplianceÊÇÒ»¿îÓÃÓÚ¹ÜÀíÆóÒµÓ¦Ó÷¨Ê½·ÃÎʵĽâ¾ö·½°¸£¬ÌṩÉí·ÝÑéÖ¤¡¢µ¥µãµÇ¼¡¢È¨ÏÞ¿ØÖƺͶàÒòËØÈÏÖ¤¹¦Ð§¡£Á½Õßͨ¹ý¼¯ÖйÜÀíÓû§·ÃÎÊȨÏÞºÍÄþ¾²¼ÆÄ±£¬È·±£ÆóÒµÓ¦ÓõÄÄþ¾²ÐÔÓëºÏ¹æÐÔ£¬¹ã·ºÓ¦ÓÃÓÚÌáÉý×éÖ¯µÄÍøÂçÄþ¾²ÐÔºÍÓû§¹ÜÀíЧÂÊ¡£


2025Äê2ÔÂ11ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½IBMÐû²¼Á˹ØÓÚCVE-2024-51450ºÍCVE-2024-49814©¶´µÄÄþ¾²Í¨¸æ¡£IBMÄþ¾²Ñé֤Ŀ¼£¨IBM Security Verify Directory£©ºÍÄþ¾²ÑéÖ¤·ÃÎÊÉ豸£¨IBM Security Verify Access Appliance£©´æÔÚÁ½¸öÑÏÖØÂ©¶´£¬¿ÉÄܱ»¹¥»÷ÕßÀûÓ㬵¼ÖÂδÊÚȨ·ÃÎʺÍÃüÁîÖ´ÐС£CVE-2024-51450ÊÇÒ»¸öÔ¶³ÌÃüÁî×¢Èë©¶´£¬ÔÊÐíÔ¶³Ì¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢Ë;«ÐĽṹµÄÇëÇó£¬ÔÚϵͳÉÏÖ´ÐÐÈÎÒâÃüÁCVSSÆÀ·ÖΪ9.1£¬Â©¶´¼¶±ðÑÏÖØ¡£CVE-2024-49814ÊÇÒ»¸öµ±µØÈ¨ÏÞÌáÉý©¶´£¬ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý²»ÐëÒªµÄȨÏÞÖ´ÐвÙ×÷£¬´Ó¶ø»ñµÃ¸ü¸ßȨÏÞ£¬¿ÉÄÜÍêÈ«¿ØÖÆÏµÍ³£¬CVSSÆÀ·ÖΪ7.8£¬Â©¶´¼¶±ð¸ßΣ¡£


¶þ¡¢Ó°Ï췶Χ


10.0.0<=IBM Security Verify Directory<=10.0.3


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


ÏÂÔØ²¢°²×°IBM Security Verify Directory°æ±¾10.0.3.1ÒÔ½â¾öÏà¹ØÄþ¾²ÎÊÌâ¡£

ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/pages/ibm-security-verify-directory-fix-level-10031-download-document/


3.2 ÁÙʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/7182558

https://nvd.nist.gov/vuln/detail/CVE-2024-51450
https://nvd.nist.gov/vuln/detail/CVE-2024-49814
https://securityonline.info/ibm-security-verify-directory-vulnerable-to-critical-security-flaw-cve-2024-51450-cvss-9-1/