WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4450£©Í¨¸æ
2020-06-05
Ò». Îó²î¸ÅÊö
±±¾©Ê±¼ä6ÔÂ5ÈÕ£¬IBM¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËWebSphere Application Server£¨WAS£©ÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2020-4450£©Îó²î£¬´ËÎó²îÓÉIIOPÐÒéÉϵķ´ÐòÁл¯Ôì³É£¬Î´¾Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPÐÒéÔ¶³Ì¹¥»÷WAS·þÎñÆ÷£¬ÔÚÄ¿µÄ·þÎñ¶ËÖ´ÐÐí§Òâ´úÂ룬»ñȡϵͳȨÏÞ£¬½ø¶ø½ÓÊÜ·þÎñÆ÷¡£CVSSÆÀ·ÖΪ9.8·Ö£¬Îó²îΣº¦½Ï¸ß¡£
WebSphere Application ServerÊÇÆóÒµ¼¶WebÖÐÐļþ£¬ÓÉÓÚÆä¿É¿¿¡¢ÎÞаºÍ½áʵµÄÌØµã£¬±»ÆÕ±éÓ¦ÓÃÓÚÆóÒµµÄWeb·þÎñÖС£Ó°ÏìÃæ½Ï´ó£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://www.ibm.com/support/pages/node/6220276
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
l WebSphere Application Server 9.0.0.0 - 9.0.5.4
l WebSphere Application Server 8.5.0.0 - 8.5.5.17
l WebSphere Application Server 8.0.0.0 - 8.0.0.15
l WebSphere Application Server 7.0.0.0 - 7.0.0.45
×¢£ºWebSphere Application Server V7.0 ºÍ V8.0¹Ù·½ÒÑ×èֹά»¤.
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
Ïà¹ØÓû§¿Éͨ¹ý°æ±¾¼ì²âµÄ·½·¨ÅжÏÄ¿½ñÓ¦ÓÃÊÇ·ñ±£´æÎ£º¦¡£
ÒªÁìÒ»£ºµÇ¼websphereÖÎÀíÆ½Ì¨Ê×Ò³Éó²é°æ±¾ÐÅÏ¢¡£

ÈôÄ¿½ñʹÓð汾ÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬Ôò¿ÉÄܱ£´æÇ徲Σº¦¡£
ÒªÁì¶þ£º½øÈë/opt/IBM/WebSphere/AppServer/binĿ¼Ï£¬Ö´ÐÐ./versionInfo.sh¼´¿ÉÉó²éÄ¿½ñ°æ±¾£¬Éó²éPackageÈÕÆÚ£¬ÈôÊǵÍÓÚ20200603Ôò˵Ã÷±£´æÇ徲Σº¦¡£
|
./versionInfo.sh |

ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Á˸ÃÎó²î£¬¹ØÓÚÒÑ×èֹά»¤µÄ°æ±¾Ò²ÌṩÁËÇå¾²²¹¶¡£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì×°ÖþÙÐзÀ»¤¡£
Ïà¹ØÓû§¿Éͨ¹ýIBM Installation Manager¾ÙÐÐÉý¼¶£¬Æ¾Ö¤ÌáÐѾÙÐа汾¸üС¢²¹¶¡×°Öá£

Óû§Ò²¿ÉÖÁ¹ÙÍøÊÖ¶¯ÏÂÔØ²¹¶¡²¢×°Öá£

×¢£º×°Öò¹¶¡Ö®Ç°ÇëÏȹرÕWebSphere·þÎñ£¬×°ÖÃÍê³ÉºóÔÙ½«·þÎñ¿ªÆô¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







