¡¾Ô­´´Îó²î¡¿WebSphereÎó²î£¨CVE-2019-4505£©

Ðû²¼Ê±¼ä 2019-09-20

0x01 Îó²îÐÎò


IBM ¹Ù·½Ðû²¼µÄWebsphere×îÐÂÇå¾²²¹¶¡ÖаüÀ¨¿­·¢k8ADLab·¢Ã÷²¢µÚһʱ¼äÌá½»¸ø¹Ù·½µÄÇå¾²Îó²î£¬ £¬ £¬Îó²î±àºÅΪCVE-2019-4505¡£¡£ ¡£¡£¡£¡£¡£¡£Í¨¹ý¸ÃÎó²î£¬ £¬ £¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½Ê¹Óᣡ£ ¡£¡£¡£¡£¡£¡£¸ÃÎó²îΣº¦½Ï´ó£¬ £¬ £¬½¨ÒéʵʱÉý¼¶×îÐÂÇå¾²²¹¶¡¡£¡£ ¡£¡£¡£¡£¡£¡£


0x02 Îó²îʱ¼äÖá


2019Äê7ÔÂ19ÈÕ£¬ £¬ £¬ADLab½«Îó²îÏêÇéÌá½»¸øIBM¹Ù·½£»£»£»£»£»£»£»£»

2019Äê7ÔÂ30ÈÕ£¬ £¬ £¬IBM¹Ù·½È·ÈÏÎó²î±£´æ²¢×îÏÈ×ÅÊÖÐÞ¸´£»£»£»£»£»£»£»£»

2019Äê9ÔÂ18ÈÕ£¬ £¬ £¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½ÖÂл¡£¡£ ¡£¡£¡£¡£¡£¡£


0x03 Ó°Ïì°æ±¾


WebSphere Application Server Version 9.0

WebSphere Application Server Version 8.5

WebSphere Application Server Version 8.0

WebSphere Application Server Version 7.0

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£¡£ ¡£¡£¡£¡£¡£¡£


0x04 Îó²î¸´ÏÖ


²âÊÔÇéÐΣºWindows7 + WebSphere 8.5


Îó²î¸´ÏÖ£º


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



0x05 ¹æ±Ü¼Æ»®


Éý¼¶²¹¶¡¡£¡£ ¡£¡£¡£¡£¡£¡£IBM¹Ù·½¸üÐÂÁ´½ÓµØµã£ºhttps://www.ibm.com/support/pages/node/964766