¡¾Ô­´´·ì϶¡¿WebSphere·ì϶£¨CVE-2019-4505£©

°ä²¼¹¦·ò 2019-09-20

0x01 ·ì϶ÃèÊö


IBM ¹Ù·½°ä²¼µÄWebsphere×îа²È«²¹¶¡ÖÐÔ̺¬OG¶«·½ÌüADLab·¢ÏÖ²¢µÚÒ»¹¦·òÌá½»¸ø¹Ù·½µÄ°²È«·ì϶£¬£¬·ì϶±àºÅΪCVE-2019-4505¡£¡£Í¨¹ý¸Ã·ì϶£¬£¬¹¥»÷ÕßÄܹ»»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½ÀûÓᣡ£¸Ã·ì϶Σº¦½Ï´ó£¬£¬½¨ÒéʵʱÉý¼¶×îа²È«²¹¶¡¡£¡£


0x02 ·ì϶¹¦·òÖá


2019Äê7ÔÂ19ÈÕ£¬£¬ADLab½«·ì϶ÏêÇéÌá½»¸øIBM¹Ù·½£»£»

2019Äê7ÔÂ30ÈÕ£¬£¬IBM¹Ù·½È·ÈÏ·ì϶´æÔÚ²¢ÆðÍ·×ÅÊÖÐÞ¸´£»£»

2019Äê9ÔÂ18ÈÕ£¬£¬ADLab»ñµÃCVE±àºÅ¼°IBM¹Ù·½³ÆÐ»¡£¡£


0x03 Ó°Ïì°æ±¾


WebSphere Application Server Version 9.0

WebSphere Application Server Version 8.5

WebSphere Application Server Version 8.0

WebSphere Application Server Version 7.0

ÒÔÉϾùΪ¹Ù·½Ö§³ÖµÄ°æ±¾¡£¡£


0x04 ·ì϶¸´ÏÖ


²âÊÔ»·¾³£ºWindows7 + WebSphere 8.5


·ì϶¸´ÏÖ£º


OG¶«·½Ìü¡¤(Öйú´ó½)



0x05 ¶ã±Ü¹æ»®


Éý¼¶²¹¶¡¡£¡£IBM¹Ù·½¸üÐÂÁ´½ÓµØÖ·£ºhttps://www.ibm.com/support/pages/node/964766