WebSphere?XMLÍⲿʵÌå×¢È루XXE£©Îó²î£¨CVE-2020-4643£©´¦Öóͷ£ÊÖ²á
2020-09-24
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬IBM¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËWebSphere Application Server£¨WAS£©ÖеÄÒ»¸öXMLÍⲿʵÌå×¢È루XXE£©Îó²î£¨CVE-2020-4643£©£¬ÓÉÓÚWASδ׼ȷ´¦Öóͷ£XMLÊý¾Ý£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔ¶³Ì»ñÈ¡·þÎñÆ÷ÉϵÄÃô¸ÐÐÅÏ¢¡£
CVE-2020-4643ÓÉAG¹«Ë¾¿Æ¼¼Çå¾²Ñо¿ÍŶӱ¨¸æ¸øIBM£¬¿ÉÒÔÓëCVE-2020-4450×éºÏʹÓõִïÎÞÐèÉí·ÝÈÏÖ¤µÄXXEÎó²î£¬Ôì³É·þÎñÆ÷Ãô¸ÐÐÅϢй¶£¬Ê¹ÓÃÖØÆ¯ºó½ÏµÍ£¬Î£º¦½Ï¸ß¡£ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
WebSphere Application ServerÊÇÆóÒµ¼¶WebÖÐÐļþ£¬ÓÉÓÚÆä¿É¿¿¡¢ÎÞаºÍ½áʵµÄÌØµã£¬±»ÆÕ±éÓ¦ÓÃÓÚÆóÒµµÄWeb·þÎñÖС£
ÎÞÐèÉí·ÝÈÏÖ¤¶ÁÈ¡·þÎñÆ÷ÐÅÏ¢¸´ÏÖ½ØÍ¼£º

²Î¿¼Á´½Ó£º
https://www.ibm.com/support/pages/security-bulletin-websphere-application-server-vulnerable-information-exposure-vulnerability-cve-2020-4643
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
WebSphere Application Server 9.0.0.0 - 9.0.5.5
WebSphere Application Server 8.5.0.0 - 8.5.5.17
WebSphere Application Server 8.0.0.0 - 8.0.0.15
WebSphere Application Server 7.0.0.0 - 7.0.0.45
×¢£ºWebSphere Application Server V7.0 ºÍ V8.0¹Ù·½ÒÑ×èֹά»¤¡£
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
Ïà¹ØÓû§¿Éͨ¹ý°æ±¾¼ì²âµÄ·½·¨ÅжÏÄ¿½ñÓ¦ÓÃÊÇ·ñ±£´æÎ£º¦¡£
ÒªÁìÒ»£ºµÇ¼websphereÖÎÀíÆ½Ì¨Ê×Ò³Éó²é°æ±¾ÐÅÏ¢¡£

ÈôÄ¿½ñʹÓð汾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Ôò¿ÉÄܱ£´æÇ徲Σº¦¡£
ÒªÁì¶þ£º½øÈë/opt/IBM/WebSphere/AppServer/binĿ¼Ï£¬Ö´ÐÐ./versionInfo.sh¼´¿ÉÉó²éÄ¿½ñ°æ±¾£¬Éó²éPackageÈÕÆÚ£¬ÈôÊǵÍÓÚ20200902Ôò˵Ã÷±£´æÇ徲Σº¦¡£
|
./versionInfo.sh |

3.2 ²úÆ·¼ì²â
AG¹«Ë¾¿Æ¼¼Ô¶³Ì×ÛºÏÍþв̽Õ루UTS£©ÒѾ߱¸¶Ô´ËÎó²îµÄ¼ì²âÄÜÁ¦£¬ÇëÓа²ÅÅ×°±¸µÄÓû§Éý¼¶ÖÁ×îа汾¡£
|
Çå¾²¼ì²â²úÆ· |
Éý¼¶°ü°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
UTS |
5.6.10.23620 |
http://update.nsfocus.com/update/downloads/id/108759 |
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Á˸ÃÎó²î£¬¹ØÓÚÒÑ×èֹά»¤µÄ°æ±¾Ò²ÌṩÁËÇå¾²²¹¶¡£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì×°ÖþÙÐзÀ»¤¡£
Ïà¹ØÓû§¿Éͨ¹ýIBM Installation Manager¾ÙÐÐÉý¼¶£¬Æ¾Ö¤ÌáÐѾÙÐа汾¸üС¢²¹¶¡×°Öá£

Óû§Ò²¿ÉÖÁ¹ÙÍøÊÖ¶¯ÏÂÔØ²¹¶¡²¢×°Öá£
|
ÊÜÓ°Ïì°æ±¾ |
ÐÞ¸´ÒªÁì |
²¹¶¡ÏÂÔØÁ´½Ó |
|
9.0.0.0 - 9.0.5.5 |
×°Öò¹¶¡PH27509 |
https://www.ibm.com/support/pages/node/6333617 |
|
8.5.0.0 - 8.5.5.17 |
×°Öò¹¶¡PH27509 |
|
|
8.0.0.0 - 8.0.0.15 |
Éý¼¶ÖÁ8.0.0.15 °æ±¾£¬²¢×°Öò¹¶¡PH27509 |
|
|
7.0.0.0 - 7.0.0.45 |
Éý¼¶ÖÁ7.0.0.45°æ±¾£¬²¢×°Öò¹¶¡PH27509 |
×¢£º×°Öò¹¶¡Ö®Ç°ÇëÏȹرÕWebSphere·þÎñ£¬×°ÖÃÍê³ÉºóÔÙ½«·þÎñ¿ªÆô¡£
4.2 ²úÆ··À»¤
Õë¶Ô´ËÎó²î£¬AG¹«Ë¾¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³£¨IPS£©ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÇëÏà¹ØÓû§Éý¼¶ÖÁ×îа汾¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ· |
¹æÔò°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
IPS |
5.6.9.23620 |
http://update.nsfocus.com/update/downloads/id/108741 |
|
5.6.10.23620 |
http://update.nsfocus.com/update/downloads/id/108742 |
²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º
IPS£ºhttps://mp.weixin.qq.com/s/JsRktENQNj1TdZSU62N0Ww
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







