IBM Spectrum Protect Plus¶à¸ö·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-4210 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4213 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4222 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4212 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4211 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


IBM Spectrum Protect Plus 10.1.0-10.1.5


·ì϶¸ÅÊö


IBM Spectrum Protect PlusÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý± £»¤Æ½Ì¨¡£¸Ãƽ̨ΪÆóÒµÌṩµ¥Ò»½ÚÔìºÍÖÎÀíµã £¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐé¹¹¡¢ÎïÀíºÍÔÆ»·¾³½øÐб¸·ÝºÍ¸´Ô­¡£


½üÈÕ £¬ZDI¹«¿ªÅû¶ÁËIBM Spectrum Protect Plus²úÆ·ÖеÄ5¸öÑϳÁ·ì϶¡£ÕâЩ·ì϶¶¼´æÔÚÓÚAdministrative Console Framework serviceÖÐ £¬¹¥»÷ÕßÀûÓÃÕâЩ·ì϶¶¼ÎÞÐèÉí·ÝÈÏÖ¤¡£¸ÅÊöÈçÏ£º


CVE-2020-4210

·ì϶ԴÓÚÔÚ½«Óû§ÌṩµÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ £¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTPºÅÁîÀûÓø÷ì϶ÔÚÊÜÓ°ÏìµÄIBM Spectrum Protect PlusÉÏÖ´ÐÐËÁÒâ´úÂë¡£


CVE-2020-4213

·ì϶ԴÓÚÔÚ½âÎöusername²ÎÊýµÄʱ³½ £¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ £¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Èç³É¹¦ÀûÓø÷ì϶ £¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÖÎÀíÔ±µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£


CVE-2020-4222

·ì϶ԴÓÚÔÚ½âÎöpassword²ÎÊýʱ £¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄ×Ö·û´®¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚrootµÄ¸ßµÍÎÄÖÐÖ´ÐдúÂë¡£


CVE-2020-4212

·ì϶ԴÓÚÔÚ½âÎöhfpackage²ÎÊýʱ £¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ £¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Èç³É¹¦ÀûÓø÷ì϶ £¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£


CVE-2020-4211

·ì϶ԴÓÚÔÚ½âÎöhostname²ÎÊýʱ £¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ £¬Î´Äܰ²Í×µØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£Èç³É¹¦ÀûÓø÷ì϶ £¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÒѰ䲼²¹¶¡½¨¸´·ì϶ £¬Á´½Ó£ºhttp://www.ibm.com/support/docview.wss?uid=ibm11072392¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-20-270/

https://www.zerodayinitiative.com/advisories/ZDI-20-271/

https://www.zerodayinitiative.com/advisories/ZDI-20-272/

https://www.zerodayinitiative.com/advisories/ZDI-20-273/

https://www.zerodayinitiative.com/advisories/ZDI-20-274/