¡¾Îó²îͨ¸æ¡¿¡¾¸üÐÂ-·ºÆðEXP¡¿Microsoft SQL Server Reporting Services Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0618£©
2020-09-21
×ÛÊö
΢ÈíÐû²¼µÄ2ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁËÒ»¸öImportant¼¶±ðµÄÎó²î£¬¸ÃÎó²îÊDZ£´æÓÚ Microsoft SQL Server Reporting Services(SSRS)ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0618£©¡£¿ËÈÕ£¬¼à²âµ½ÍøÉÏÓÐExp·ºÆð¡£
SSRSÓ¦ÓÃÖеĹ¦Ð§ÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÏòÊÜÓ°ÏìµÄReporting ServicesʵÀýÌύȫÐĽṹµÄHTTPÇëÇó£¬Ê¹ÓÃÓ¦ÓÃÖеķ´ÐòÁл¯ÎÊÌâÔÚÊÜÓ°ÏìµÄ·þÎñÆ÷ÉÏÖ´ÐдúÂë¡£
Ö»¹ÜÖ»ÓÐÊÚȨÓû§²Å»ª»á¼û¸ÃÓ¦ÓóÌÐò£¬µ«Ê¹ÓÃ×îµÍȨÏÞ£¨Browser½ÇÉ«£©×ãÒÔʹÓøÃÎó²î¡£
SQL Server Reporting Services (SSRS)ÊÇ΢Èí»ùÓÚ·þÎñÆ÷µÄ±¨±íÌìÉúÈí¼þ£¬ËüÊÇMicrosoft SQL Server·þÎñÌ×¼þµÄÒ»²¿·Ö£¬Í¨¹ýWeb½çÃæ¾ÙÐÐÖÎÀí£¬¿ÉÓÃÓÚ×¼±¸ºÍ½»¸¶ÖÖÖÖ½»»¥Ê½±¨¸æ¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618
ÊÜÓ°Ïì²úÆ·°æ±¾
Microsoft SQL Server 2012 Service Pack 4£¨QFE£©
Microsoft SQL Server 2014 Service Pack 3£¨CU£©
Microsoft SQL Server 2014 Service Pack 3£¨GDR£©
Microsoft SQL Server 2016 Service Pack 2 (CU)
Microsoft SQL Server 2016 Service Pack 2 (GDR)
½â¾ö¼Æ»®
ÓÉÓÚ¹¥»÷Õß¿Éͨ¹ý¶ÔÇëÇóÊý¾Ý°ü±àÂëÈÆ¹ýWebÓ¦Ó÷À»ðǽµÄ·À»¤£¬Ç¿ÁÒ½¨ÒéÓû§×°Öò¹¶¡¾ÙÐÐÐÞ¸´¡£
΢Èí¹Ù·½ÒÑΪÊÜÖ§³Ö°æ±¾Ðû²¼ÁËÕë¶Ô¸ÃÎó²îµÄÇå¾²²¹¶¡£¬Çë²ÎÔÄ΢Èí¹Ù·½Í¨¸æÊµÊ±ÏÂÔØ×°Öá£
×¢ÖØ£ºÈôÊÇÄúʹÓõÄSQL ServerÊÇϱíÖÐδÏÔʾµÄ°æ±¾£¬ÔòÌåÏÖËùÓð汾ÒѲ»ÔÙÊÜÖ§³Ö¡£Çë¸üÐÂService Pack»òSQL Server²úÆ·£¬ÒÔÓ¦ÓÃÇå¾²¸üС£
|
²úÆ· |
°æ±¾ |
¸üбàºÅ |
|
SQL Server 2016 Service Pack 2 (GDR) Çå¾²¸üР|
13.0.5026.0 - 13.0.5101.9 |
KB4532097 |
|
SQL Server 2016 Service Pack 2 CU11Çå¾²¸üР|
13.0.5149.0 - 13.0.5598.27 |
KB4535706 |
|
SQL Server 2014 Service Pack 3 (GDR) Çå¾²¸üР|
12.0.6024.0 - 12.0.6108.1 |
KB4532095 |
|
SQL Server 2014 Service Pack 2 CU4Çå¾²¸üР|
12.0.6205.1 - 12.0.6329.1 |
KB4535288 |
|
SQL Server 2012 Service Pack 4 (QFE) Çå¾²¸üР|
111.0.7001.0 - 11.0.7462.6 |
KB4532098 |
ͬʱ£¬½¨ÒéեȡÄäÃû»á¼û£¬È·±£Ö»ÓоÓÉÉí·ÝÑéÖ¤µÄÓû§²Å»ª»á¼ûÏà¹ØÓ¦Óá£ÈôÊÇÏÓÒÉ·þÎñÆ÷ÒѾÊܵ½Íþв£¬³ý×°ÖÃÏìÓ¦²¹¶¡Í⣬Çëʵʱ¸ü¸Ä·þÎñÆ÷µÄÕË»§¿ÚÁ±ÜÃâ±»¹¥»÷ÕßʹÓá£
¹Ù·½Í¨¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







