McAfee Database Security 6Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-06-07

0x00 ·ì϶¸ÅÊö

McAfee Êý¾Ý¿â°²È«²úÆ·¿ÉÄÜʵʱ±£»¤¹Ø¼üÒµÎñµÄÊý¾Ý¿â£¬Ô¤·ÀÆäÔâ·ê±í²¿¡¢ÄÚ²¿ºÍÊý¾Ý¿âÄÚ²¿µÄ¸÷À๥»÷¡£

2021Äê06ÔÂ01ÈÕ£¬McAfee°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËDatabase SecurityÖеÄ5¸ö°²È«·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶δÊÚȨ½Ó¼û¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½ÚÔì·þÎñÆ÷¡£

 

0x01 ·ì϶ÏêÇé

image.png

±¾´Î½¨¸´µÄ5¸ö·ì϶ÖУ¬CVE-2021-23894ºÍCVE-2021-23895ÊÇMcAfee Database Security £¨DBSec£©Öеķ´ÐòÁл¯·ì϶£¬Î´¾­ÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâ¹¹½¨µÄJavaÐòÁл¯¶ÔÏóµ½DBSec·þÎñÆ÷À´´¥·¢´Ë·ì϶£¬²¢Í¨¹ýÔÚDBSec·þÎñÆ÷ÉÏ´´½¨ÓµÓÐÖÎÀíԱȨÏ޵ķ´ÏòshellÀ´½ÚÔì·þÎñÆ÷¡£

CVE-2021-31830ÊÇDBSecÖеÄXSS·ì϶£¬Õ¼ÓÐÖÎÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»Í¨¹ýÔÚÅäÖÃÒª¼à¿ØµÄÊý¾Ý¿âÃû³ÆÊ±Ç¶ÈëJavaScript´úÂ룬µ±ÈκÎÊÚȨÓû§µÇ¼µ½DBSec½çÃæ²¢´ò¿ª¸ÃÊý¾Ý¿âµÄÊôÐÔÅäÖÃÒ³ÃæÊ±£¬½«´¥·¢¶ñÒâ´úÂ룬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£

CVE-2021-31831ÊÇDBSecÖÐÒÑɾ³ý¾ç±¾µÄ²»ÕýÈ·½Ó¼û·ì϶£¬ÕâЩ¾ç±¾±»±£ÁôÏÂÀ´£¬ÒÔ±ãÔÚ½«À´±ØÒª·ÖÎöÍùÊÂÎñʱʹÓᣵ«¾­¹ýÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýREST API»ñµÃ¶ÔÖÎÀí½ÚÔį̀ÖÐÒÑÏóÕ÷Ϊɾ³ý»ò¹ýÆÚµÄÊðÃûSQL¾ç±¾µÄ½Ó¼û£¬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£

CVE-2021-23896ÊÇDBSecÖÎÀíÔ±½çÃæÖеÄÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä·ì϶£¬Õ¼ÓÐÖÎÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»ÀûÓô˷ì϶²é¿´McAfee Insights ServerµÄδ¼ÓÃÜÃÜÂ룬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£

 

CVE-ID

ÀàÐÍ

CVSSv3ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2021-23894

·´ÐòÁл¯

9.6

<   4.8.2

CVE-2021-23895

·´ÐòÁл¯

9.0

CVE-2021-23896

ÐÅϢй¶

3.2

CVE-2021-31830

XSS

5.9

CVE-2021-31831

½Ó¼û½ÚÔìÃýÎó

4.9

 

 

0x02 ´ëÖý¨Òé

ĿǰMcAfeeÒѾ­ÔÚDBSec 4.8.2Öн¨¸´ÁËÕâЩ·ì϶£¬½¨ÒéʵʱÉý¼¶¸üУº

ÏÂÔØÏνӣº

https://www.mcafee.com/enterprise/en-us/downloads.html

 

0x03 ²Î¿¼Á´½Ó

https://kc.mcafee.com/corporate/index?page=content&id=SB10359#Remediation

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23894

https://nvd.nist.gov/vuln/detail/CVE-2021-23894

 

0x04 ¹¦·òÏß

2021-06-01  McAfee°ä²¼°²È«²¼¸æ

2021-06-02  McAfee¸üа²È«²¼¸æ

2021-06-07  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png