McAfee Database Security 6Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-06-070x00 ·ì϶¸ÅÊö
McAfee Êý¾Ý¿â°²È«²úÆ·¿ÉÄÜʵʱ±£»¤¹Ø¼üÒµÎñµÄÊý¾Ý¿â£¬Ô¤·ÀÆäÔâ·ê±í²¿¡¢ÄÚ²¿ºÍÊý¾Ý¿âÄÚ²¿µÄ¸÷À๥»÷¡£
2021Äê06ÔÂ01ÈÕ£¬McAfee°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËDatabase SecurityÖеÄ5¸ö°²È«·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶δÊÚȨ½Ó¼û¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½ÚÔì·þÎñÆ÷¡£
0x01 ·ì϶ÏêÇé

±¾´Î½¨¸´µÄ5¸ö·ì϶ÖУ¬CVE-2021-23894ºÍCVE-2021-23895ÊÇMcAfee Database Security £¨DBSec£©Öеķ´ÐòÁл¯·ì϶£¬Î´¾ÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâ¹¹½¨µÄJavaÐòÁл¯¶ÔÏóµ½DBSec·þÎñÆ÷À´´¥·¢´Ë·ì϶£¬²¢Í¨¹ýÔÚDBSec·þÎñÆ÷ÉÏ´´½¨ÓµÓÐÖÎÀíԱȨÏ޵ķ´ÏòshellÀ´½ÚÔì·þÎñÆ÷¡£
CVE-2021-31830ÊÇDBSecÖеÄXSS·ì϶£¬Õ¼ÓÐÖÎÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»Í¨¹ýÔÚÅäÖÃÒª¼à¿ØµÄÊý¾Ý¿âÃû³ÆÊ±Ç¶ÈëJavaScript´úÂ룬µ±ÈκÎÊÚȨÓû§µÇ¼µ½DBSec½çÃæ²¢´ò¿ª¸ÃÊý¾Ý¿âµÄÊôÐÔÅäÖÃÒ³ÃæÊ±£¬½«´¥·¢¶ñÒâ´úÂ룬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£
CVE-2021-31831ÊÇDBSecÖÐÒÑɾ³ý¾ç±¾µÄ²»ÕýÈ·½Ó¼û·ì϶£¬ÕâЩ¾ç±¾±»±£ÁôÏÂÀ´£¬ÒÔ±ãÔÚ½«À´±ØÒª·ÖÎöÍùÊÂÎñʱʹÓᣵ«¾¹ýÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýREST API»ñµÃ¶ÔÖÎÀí½ÚÔį̀ÖÐÒÑÏóÕ÷Ϊɾ³ý»ò¹ýÆÚµÄÊðÃûSQL¾ç±¾µÄ½Ó¼û£¬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£
CVE-2021-23896ÊÇDBSecÖÎÀíÔ±½çÃæÖеÄÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä·ì϶£¬Õ¼ÓÐÖÎÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»ÀûÓô˷ì϶²é¿´McAfee Insights ServerµÄδ¼ÓÃÜÃÜÂ룬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£
CVE-ID | ÀàÐÍ | CVSSv3ÆÀ·Ö | Ó°ÏìÁìÓò |
CVE-2021-23894 | ·´ÐòÁл¯ | 9.6 | < 4.8.2 |
CVE-2021-23895 | ·´ÐòÁл¯ | 9.0 | |
CVE-2021-23896 | ÐÅϢй¶ | 3.2 | |
CVE-2021-31830 | XSS | 5.9 | |
CVE-2021-31831 | ½Ó¼û½ÚÔìÃýÎó | 4.9 |
0x02 ´ëÖý¨Òé
ĿǰMcAfeeÒѾÔÚDBSec 4.8.2Öн¨¸´ÁËÕâЩ·ì϶£¬½¨ÒéʵʱÉý¼¶¸üУº
ÏÂÔØÏνӣº
https://www.mcafee.com/enterprise/en-us/downloads.html
0x03 ²Î¿¼Á´½Ó
https://kc.mcafee.com/corporate/index?page=content&id=SB10359#Remediation
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23894
https://nvd.nist.gov/vuln/detail/CVE-2021-23894
0x04 ¹¦·òÏß
2021-06-01 McAfee°ä²¼°²È«²¼¸æ
2021-06-02 McAfee¸üа²È«²¼¸æ
2021-06-07 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ