CVE-2020-4464 | WebSphere Application ServerÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ

°ä²¼¹¦·ò 2020-07-23

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-4464

ʱ    ¼ä

2020-07-23

Àà   ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

WebSphere Application Server 9.0,8.5,8.0,7.0


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2020Äê7ÔÂ16ÈÕ£¬IBM°ä²¼ÁËÒ»¸ö°²È«¸üУ¬½¨¸´ÁËÒ»¸öWebSphere Application ServerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4464£©¡£¸Ã·ì϶µ¼Ö¹¥»÷Õ߿ɻú¹ØÒ»¸ö¶ñÒâµÄÐòÁл¯¶ÔÏ󣬲¢Í¨¹ýSOAPÏÎ½ÓÆ÷À´Ö´ÐÐËÁÒâJAVA´úÂë¡£


0x02 ´ëÖý¨Òé


V9.0.0.0ÖÁ9.0.5.4£¬ÓÐÁ½ÖÖ½¨¸´¹æ»®£º

? ³§ÉÌÒѰ䲼²¹¶¡£¬²¹¶¡ÏÂÔØ£º

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=9.0.5.3-WS-WAS-IFPH26952&includeSupersedes=0

? Éý¼¶µ½9.0.5.5»ò¸ü¸ß°æ±¾£¨Ö¸±ê¿ÉÓÃÐÔΪ2020ÄêµÚÈý¼¾¶È£©¡£

V8.5.0.0ÖÁ8.5.5.17£¬ÓÐÁ½ÖÖ½¨¸´¹æ»®£º

? ³§ÉÌÒѰ䲼²¹¶¡£¬²¹¶¡ÏÂÔØ£º

http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.5.5.14-WS-WAS-IFPH26952&includeSupersedes=0

? Éý¼¶µ½8.5.5.18»ò¸ü¸ß°æ±¾£¨Ö¸±ê¿ÉÓÃÐÔΪ2020ÄêµÚÈý¼¾¶È£©¡£

V8.0.0.0ÖÁ8.0.0.15£º

? Éý¼¶µ½8.0.0.15£¬¶øºó²Î¿¼£º

http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=8.0.0.15-WS-WAS-IFPH26952&includeSupersedes=0

V7.0.0.0ÖÁ7.0.0.45£º

? Éý¼¶µ½7.0.0.45£¬¶øºó²Î¿¼£º

http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%2FWebSphere&product=ibm/WebSphere/WebSphere+Application+Server&release=All&platform=All&function=fixId&fixids=7.0.0.45-WS-WAS-IFPH26952&includeSupersedes=0

°ÑÎÈ£ºWebSphere Application Server V7.0ºÍV8.0ÒѲ»ÔÙÊØ»¤¡£


0x03 ÓйØÐÂÎÅ


https://www.hkcert.org/my_url/en/alert/20072001


0x04 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/6250059


0x05 ¹¦·òÏß


2020-07-23 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾