¡¾Îó²îͨ¸æ¡¿IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î(CVE-2024-51450)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î

CVE   ID

CVE-2024-51450

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


IBM Security Verify DirectoryÊÇÒ»¿îÆóÒµ¼¶Éí·ÝºÍ»á¼ûÖÎÃ÷È·¾ö¼Æ»®£¬£¬£¬ £¬£¬ £¬£¬£¬ÌṩÇå¾²µÄÓû§Éí·ÝÖÎÀíºÍĿ¼ЧÀÍ£¬£¬£¬ £¬£¬ £¬£¬£¬Ö§³ÖÖØ´óµÄÈÏÖ¤ºÍÊÚȨÐèÇ󣬣¬£¬ £¬£¬ £¬£¬£¬×ÊÖú×éÖ¯±£»£»£»£» £»£»£»£»¤Ãô¸ÐÊý¾Ý¡£¡£ ¡£IBM Security Verify Access ApplianceÊÇÒ»¿îÓÃÓÚÖÎÀíÆóÒµÓ¦ÓóÌÐò»á¼ûµÄ½â¾ö¼Æ»®£¬£¬£¬ £¬£¬ £¬£¬£¬ÌṩÉí·ÝÑéÖ¤¡¢µ¥µãµÇ¼¡¢È¨ÏÞ¿ØÖƺͶàÒòËØÈÏÖ¤¹¦Ð§¡£¡£ ¡£Á½Õßͨ¹ý¼¯ÖÐÖÎÀíÓû§»á¼ûȨÏÞºÍÇå¾²Õ½ÂÔ£¬£¬£¬ £¬£¬ £¬£¬£¬È·±£ÆóÒµÓ¦ÓõÄÇå¾²ÐÔÓëºÏ¹æÐÔ£¬£¬£¬ £¬£¬ £¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÌáÉý×éÖ¯µÄÍøÂçÇå¾²ÐÔºÍÓû§ÖÎÀíЧÂÊ¡£¡£ ¡£


2025Äê2ÔÂ11ÈÕ£¬£¬£¬ £¬£¬ £¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍø¼¯ÍÅVSRC¼à²âµ½IBMÐû²¼Á˹ØÓÚCVE-2024-51450ºÍCVE-2024-49814Îó²îµÄÇ徲ͨ¸æ¡£¡£ ¡£IBMÇå¾²Ñé֤Ŀ¼£¨IBM Security Verify Directory£©ºÍÇå¾²ÑéÖ¤»á¼û×°±¸£¨IBM Security Verify Access Appliance£©±£´æÁ½¸öÑÏÖØÎó²î£¬£¬£¬ £¬£¬ £¬£¬£¬¿ÉÄܱ»¹¥»÷ÕßʹÓ㬣¬£¬ £¬£¬ £¬£¬£¬µ¼ÖÂδÊÚȨ»á¼ûºÍÏÂÁîÖ´ÐС£¡£ ¡£CVE-2024-51450ÊÇÒ»¸öÔ¶³ÌÏÂÁî×¢ÈëÎó²î£¬£¬£¬ £¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬣¬£¬ £¬£¬ £¬£¬£¬ÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬ £¬£¬ £¬£¬£¬CVSSÆÀ·ÖΪ9.1£¬£¬£¬ £¬£¬ £¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£ ¡£CVE-2024-49814ÊÇÒ»¸öÍâµØÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬ £¬£¬ £¬£¬£¬ÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý²»ÐëÒªµÄȨÏÞÖ´ÐвÙ×÷£¬£¬£¬ £¬£¬ £¬£¬£¬´Ó¶ø»ñµÃ¸ü¸ßȨÏÞ£¬£¬£¬ £¬£¬ £¬£¬£¬¿ÉÄÜÍêÈ«¿ØÖÆÏµÍ³£¬£¬£¬ £¬£¬ £¬£¬£¬CVSSÆÀ·ÖΪ7.8£¬£¬£¬ £¬£¬ £¬£¬£¬Îó²î¼¶±ð¸ßΣ¡£¡£ ¡£


¶þ¡¢Ó°Ïì¹æÄ£


10.0.0<=IBM Security Verify Directory<=10.0.3


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÂÔØ²¢×°ÖÃIBM Security Verify Directory°æ±¾10.0.3.1ÒÔ½â¾öÏà¹ØÇå¾²ÎÊÌâ¡£¡£ ¡£

ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/pages/ibm-security-verify-directory-fix-level-10031-download-document/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£ ¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ £¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ £¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£ ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬ £¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬ £¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ £¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ £¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£ ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ £¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£ ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ £¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬ £¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£ ¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£ ¡£


3.4 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/7182558

https://nvd.nist.gov/vuln/detail/CVE-2024-51450
https://nvd.nist.gov/vuln/detail/CVE-2024-49814
https://securityonline.info/ibm-security-verify-directory-vulnerable-to-critical-security-flaw-cve-2024-51450-cvss-9-1/