WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4534£©Í¨¸æ
2020-08-10
Ò». Îó²î¸ÅÊö
±±¾©Ê±¼ä2020Äê7ÔÂ31ÈÕ£¬IBM¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁËWebSphere Application Server£¨WAS£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4534£©¡£¸ÃÎó²îÓÉÓÚδ׼ȷ´¦Öóͷ£UNC·¾¶¶øµ¼Ö£¬¾ÓÉÍâµØÉí·ÝÈÏÖ¤ºó£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÍê³É´úÂëÖ´ÐУ¬Îó²îÆÀ·ÖΪ7.8·Ö¡£
¸ÃÎó²î£¨CVE-2020-4534£©ÓÉAG¹«Ë¾¿Æ¼¼·üӰʵÑéÊÒ·¢Ã÷²¢Ìá½»ÖÁIBM¡£¾×¨¼ÒÅжϣ¬¸ÃÎó²î¿ÉÒÔÓë´ËǰAG¹«Ë¾¿Æ¼¼Ìá½»ÖÁIBMµÄCVE-2020-4450×éºÏʹÓã¬ÎÞÐèÉí·ÝÈÏÖ¤¼´¿ÉÔÚÄ¿µÄ·þÎñ¶ËÖ´ÐÐí§Òâ´úÂ룬»ñȡϵͳȨÏÞ£¬½ø¶ø½ÓÊÜ·þÎñÆ÷¡£ÇëÏà¹ØÓû§¾¡¿ìÐÞ¸´´ËÎó²î£¬ÒÔ»º½â´ËÎó²î´øÀ´µÄΣº¦¡£

²Î¿¼Á´½Ó£º
https://www.ibm.com/support/pages/node/6255074
https://www.ibm.com/support/pages/node/6254980
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
WebSphere Application Server 9.0
WebSphere Application Server 8.5
WebSphere Application Server 8.0
WebSphere Application Server 7.0
Èý. Îó²î¼ì²â
3.1 °æ±¾¼ì²â
Óû§¿Éͨ¹ýIBM Installation Manager->¸üУ¬Éó²éÒÑ×°ÖõÄÈí¼þ°üºÍÐÞ¶©£¬¼ì²éÄ¿½ñÊÇ·ñÒÑ×°Öò¹¶¡PH26092¡£Èô±£´æ¸Ã²¹¶¡ÐÅÏ¢£¬Ôò²»ÊÜÎó²îÓ°Ïì¡£

Óû§Ò²¿Éͨ¹ýÉó²éInstallation ManagerĿ¼ÏµÄinstalled.xmlÎļþ£¬ËÑË÷PH26083¼ì²éÄ¿½ñÊÇ·ñ×°Öò¹¶¡£¬Èô±£´æPH26083²¹¶¡ÐÅÏ¢£¬ÔòÄ¿½ñ²»ÊÜÎó²îÓ°Ïì¡£

ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´Á˸ÃÎó²î£¬¹ØÓÚÒÑ×èֹά»¤µÄ°æ±¾Ò²ÌṩÁËÇå¾²²¹¶¡£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì×°ÖþÙÐзÀ»¤¡£
Ïà¹ØÓû§¿Éͨ¹ýIBM Installation Manager¾ÙÐÐÉý¼¶£¬Æ¾Ö¤ÌáÐѾÙÐа汾¸üС¢×°Öò¹¶¡PH26083¡£

Óû§Ò²¿ÉÖÁ¹ÙÍøÊÖ¶¯ÏÂÔØ²¹¶¡²¢×°Öá£
²¹¶¡ÏÂÔØÁ´½Ó£ºhttps://www.ibm.com/support/pages/node/6254980
×¢£º×°Öò¹¶¡Ö®Ç°ÇëÏȹرÕWebSphere·þÎñ£¬×°ÖÃÍê³ÉºóÔÙ½«·þÎñ¿ªÆô¡£
4.2 ²úÆ··À»¤
AG¹«Ë¾¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³£¨IPS£©¡¢ÍøÂçÈëÇÖ¼ì²âϵͳ£¨IDS£©µÄÓû§¿Éͨ¹ýÉý¼¶¹æÔò°üÖÁ×îа汾£¬ÊµÏÖ¶Ô´ËÎó²îʹÓÃÐÐΪµÄ¼ì²â·À»¤ÄÜÁ¦¡£Çå¾²²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ· |
¹æÔò°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
¹æÔò±àºÅ |
|
IPS¡¢IDS |
5.6.10.23150 |
http://update.nsfocus.com/update/downloads/id/107144 |
¡¾24981¡¿CVE-2020-4534£»
¡¾24980¡¿CVE-2020-4450 |
|
5.6.9.23150 |
http://update.nsfocus.com/update/downloads/id/107143 |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







