IBM Spectrum Protect Plus¶à¸öÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-4210£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4213£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4222£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4212£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4211£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


IBM Spectrum Protect Plus 10.1.0-10.1.5


Îó²î¸ÅÊö


IBM Spectrum Protect PlusÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý±£»£»£»¤Æ½Ì¨¡£¡£¡£¡£¡£¡£¸Ãƽ̨ΪÆóÒµÌṩ¼òµ¥¿ØÖƺÍÖÎÀíµã£¬£¬£¬£¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐéÄâ¡¢ÎïÀíºÍÔÆÇéÐξÙÐб¸·ÝºÍ»Ö¸´¡£¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬ZDI¹ûÕæÅû¶ÁËIBM Spectrum Protect Plus²úÆ·ÖеÄ5¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¶¼±£´æÓÚAdministrative Console Framework serviceÖУ¬£¬£¬£¬¹¥»÷ÕßʹÓÃÕâЩÎó²î¶¼ÎÞÐèÉí·ÝÈÏÖ¤¡£¡£¡£¡£¡£¡£¸ÅÊöÈçÏ£º


CVE-2020-4210

Îó²îÔ´ÓÚÔÚ½«Óû§ÌṩµÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTPÏÂÁîʹÓøÃÎó²îÔÚÊÜÓ°ÏìµÄIBM Spectrum Protect PlusÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4213

Îó²îÔ´ÓÚÔÚÆÊÎöusername²ÎÊýµÄʱ¼ä£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÖÎÀíÔ±µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4222

Îó²îÔ´ÓÚÔÚÆÊÎöpassword²ÎÊýʱ£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄ×Ö·û´®¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4212

Îó²îÔ´ÓÚÔÚÆÊÎöhfpackage²ÎÊýʱ£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


CVE-2020-4211

Îó²îÔ´ÓÚÔÚÆÊÎöhostname²ÎÊýʱ£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Îó²î£¬£¬£¬£¬Á´½Ó£ºhttp://www.ibm.com/support/docview.wss?uid=ibm11072392¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-20-270/

https://www.zerodayinitiative.com/advisories/ZDI-20-271/

https://www.zerodayinitiative.com/advisories/ZDI-20-272/

https://www.zerodayinitiative.com/advisories/ZDI-20-273/

https://www.zerodayinitiative.com/advisories/ZDI-20-274/