IBM Spectrum Protect Plus¶à¸öÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-4210£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4213£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4222£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4212£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8

CVE±àºÅ£ºCVE-2020-4211£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


IBM Spectrum Protect Plus 10.1.0-10.1.5


Îó²î¸ÅÊö


IBM Spectrum Protect PlusÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý±£»£»£»£»£»¤Æ½Ì¨¡£¡£¡£¸Ãƽ̨ΪÆóÒµÌṩ¼òµ¥¿ØÖƺÍÖÎÀíµã£¬£¬£¬£¬£¬£¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐéÄâ¡¢ÎïÀíºÍÔÆÇéÐξÙÐб¸·ÝºÍ»Ö¸´¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬£¬£¬ZDI¹ûÕæÅû¶ÁËIBM Spectrum Protect Plus²úÆ·ÖеÄ5¸öÑÏÖØÎó²î¡£¡£¡£ÕâЩÎó²î¶¼±£´æÓÚAdministrative Console Framework serviceÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÕâЩÎó²î¶¼ÎÞÐèÉí·ÝÈÏÖ¤¡£¡£¡£¸ÅÊöÈçÏ£º


CVE-2020-4210

Îó²îÔ´ÓÚÔÚ½«Óû§ÌṩµÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTPÏÂÁîʹÓøÃÎó²îÔÚÊÜÓ°ÏìµÄIBM Spectrum Protect PlusÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


CVE-2020-4213

Îó²îÔ´ÓÚÔÚÆÊÎöusername²ÎÊýµÄʱ¼ä£¬£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÖÎÀíÔ±µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


CVE-2020-4222

Îó²îÔ´ÓÚÔÚÆÊÎöpassword²ÎÊýʱ£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄ×Ö·û´®¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£¡£¡£


CVE-2020-4212

Îó²îÔ´ÓÚÔÚÆÊÎöhfpackage²ÎÊýʱ£¬£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


CVE-2020-4211

Îó²îÔ´ÓÚÔÚÆÊÎöhostname²ÎÊýʱ£¬£¬£¬£¬£¬£¬ÔÚ½«Óû§Ìá½»µÄ×Ö·û´®ÓÃÓÚÖ´ÐÐϵͳŲÓÃ֮ǰ£¬£¬£¬£¬£¬£¬Î´ÄÜÎÈÍâµØÑéÖ¤Óû§Ìá½»µÄÊäÈë¡£¡£¡£ÈçÀÖ³ÉʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚrootµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttp://www.ibm.com/support/docview.wss?uid=ibm11072392¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/ZDI-20-270/

https://www.zerodayinitiative.com/advisories/ZDI-20-271/

https://www.zerodayinitiative.com/advisories/ZDI-20-272/

https://www.zerodayinitiative.com/advisories/ZDI-20-273/

https://www.zerodayinitiative.com/advisories/ZDI-20-274/