vRealize Operations for Horizon Adapter Çå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-24

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-3943 £¬ £¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬ £¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.0 £¬ £¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3944 £¬ £¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ £¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6 £¬ £¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3945 £¬ £¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬ £¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3 £¬ £¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vRealize Operations for Horizon Adapter <= 6.6.0

vRealize Operations for Horizon Adapter <= 6.7.0


Îó²î¸ÅÊö


VMware vRealize Suite ÊÇרΪ»ìÏýÔÆ¶ø¹¹½¨µÄÔÆÖÎÀíÆ½Ì¨¡£¡£¡£¡£¡£¡£VMware Horizon ÊÇÓÉ vmware ¹«Ë¾ÍƳöµÄÒ»¿îÕë¶ÔWindows¡¢Linux¼°Mac OS X £¬ £¬£¬£¬£¬£¬£¬Ëù¿ª·¢µÄÐéÄâ×ÀÃæÈí¼þ¡£¡£¡£¡£¡£¡£


¿ËÈÕ £¬ £¬£¬£¬£¬£¬£¬vmware ¹Ù·½Ðû²¼Á˱àºÅΪ VMSA-2020-0003 µÄÇå¾²¸üС£¡£¡£¡£¡£¡£ÆäÖаüÀ¨ÑÏÖØÎó²îCVE-2020-3943¡¢¸ßΣÎó²îCVE-2020-3944ºÍÖÐΣÎó²îCVE-2020-3945 £¬ £¬£¬£¬£¬£¬£¬¸ÅÊöÈçÏ£º


CVE-2020-3943


¸ÃÎó²î·ºÆðÔÚ vRealize ×é¼þÔÚʵÏÖºÍ Horizon ×é¼þ¾ÙÐÐЭ×÷µÄʱ¼ä £¬ £¬£¬£¬£¬£¬£¬¸ÃЭ×÷³ÌÐòÆôÓÃÁ˲»Çå¾²µÄ JMX RMI ЧÀÍ £¬ £¬£¬£¬£¬£¬£¬½ø¶øµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²îµÄ·ºÆð¡£¡£¡£¡£¡£¡£


JMX£¨Java Management Extensions £¬ £¬£¬£¬£¬£¬£¬¼´JavaÖÎÀíÀ©Õ¹£©ÊÇJavaƽ̨ÉÏΪӦÓóÌÐò¡¢×°±¸¡¢ÏµÍ³µÈÖ²ÈëÖÎÀí¹¦Ð§µÄ¿ò¼Ü¡£¡£¡£¡£¡£¡£JMX¿ÉÒÔ¿çԽһϵÁÐÒì¹¹²Ù×÷ϵͳƽ̨¡¢ÏµÍ³ÏµÍ³½á¹¹ºÍÍøÂç´«ÊäЭÒé £¬ £¬£¬£¬£¬£¬£¬ÎÞаµÄ¿ª·¢Î޷켯³ÉµÄϵͳ¡¢ÍøÂçºÍЧÀÍÖÎÀíÓ¦Óᣡ£¡£¡£¡£¡£


CVE-2020-3944


vRealize Operations for Horizon Adapter¾ßÓв»×¼È·µÄÐÅÈδ洢ÉèÖà £¬ £¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÈÆ¹ýÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£


CVE-2020-3945


¸ÃÎó²îµÄÔµ¹ÊÔ­ÓÉÊÇHorizonÊÊÅäÆ÷µÄvRealize²Ù×÷ÓëHorizonÊÓͼ֮¼äµÄÅä¶ÔʵÏÖ²»×¼È· £¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÐÅÏ¢×ß©¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î £¬ £¬£¬£¬£¬£¬£¬Çë¸üÐÂÖÁ6.6.1ºÍ6.7.1 £¬ £¬£¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://www.vmware.com/security/advisories/VMSA-2020-0003.html¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0003.html