IBM Spectrum Protect Plus¶à¸öÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-4210£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4213£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4222£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4212£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4211£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


IBM Spectrum Protect Plus 10.1.0-10.1.5


Îó²î¸ÅÊö


IBM Spectrum Protect PlusÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý±£»£»£»£»¤Æ½Ì¨¡£¡£¡£¡£¡£¡£¸Ãƽ̨ΪÆóÒµÌṩ¼òµ¥¿ØÖƺÍÖÎÀíµã£¬£¬£¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐéÄâ¡¢ÎïÀíºÍÔÆÇéÐξÙÐб¸·ÝºÍ»Ö¸´¡£¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬ZDI¹ûÕæÅû¶ÁËIBM Spectrum Protect Plus²úÆ·ÖеÄ5¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¶¼±£´æÓÚAdministrative Console Framework serviceÖУ¬£¬£¬¹¥»÷ÕßʹÓÃÕâЩÎó²î¶¼ÎÞÐèÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º


CVE-2020-4210

Îó²îÔ´ÓÚÔÚ½«Óû§ÌṩµÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTPÏÂÁîʹÓøÃÎó²îÔÚÊÜÓ°ÏìµÄIBM Spectrum Protect PlusÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4213

Îó²îÔ´ÓÚÔÚÆÊÎöusername²ÎÊýµÄʱ¼ä£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÖÎÀíÔ±µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4222

Îó²îÔ´ÓÚÔÚÆÊÎöpassword²ÎÊýʱ£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄ×Ö·û´®¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4212

Îó²îÔ´ÓÚÔÚÆÊÎöhfpackage²ÎÊýʱ£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4211

Îó²îÔ´ÓÚÔÚÆÊÎöhostname²ÎÊýʱ£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Îó²î£¬£¬£¬Á´½Ó£ºhttp://www.ibm.com/support/docview.wss?uid=ibm11072392¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-20-270/

https://www.zerodayinitiative.com/advisories/ZDI-20-271/

https://www.zerodayinitiative.com/advisories/ZDI-20-272/

https://www.zerodayinitiative.com/advisories/ZDI-20-273/

https://www.zerodayinitiative.com/advisories/ZDI-20-274/