IBM ϵÁвúÆ·¶à¸ö·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-05

·ì϶±àºÅºÍ¼¶±ð



CVE±àºÅ£ºCVE-2019-4087£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬£¬£¬£¬£¬¹Ù·½£º9.8
CVE±àºÅ£ºCVE-2019-4088£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.4£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-4140£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.3£¬£¬£¬£¬£¬¹Ù·½£º7.1
CVE±àºÅ£ºCVE-2019-4129£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º3.1£¬£¬£¬£¬£¬¹Ù·½£º5.3
CVE±àºÅ£ºCVE-2019-4292£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬¹Ù·½£º8.8 
CVE±àºÅ£ºCVE-2019-4134£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.1£¬£¬£¬£¬£¬¹Ù·½£º6.1

CVE±àºÅ£ºCVE-2019-4260£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3£¬£¬£¬£¬£¬¹Ù·½£º5.3



Ó°Ïì°æ±¾



ÊÜÓ°ÏìµÄ°æ±¾


CVE-2019-4087¡¢CVE-2019-4088¡¢CVE-2019-4140¡¢CVE-2019-4129£º

IBM Spectrum Protect
8.1.0.0 through 8.1.7.xxx
7.1.0.0 through 7.1.9.200
CVE-2019-4292£º
IBM Security Guardium 10.5
CVE-2019-4134£º
IBM Planning Analytics Local v2.0
CVE-2019-4260£º

Daeja ViewONE Virtual 5.0 - 5.0.5



·ì϶¸ÅÊö



IBMÅû¶ÁËÆäһϵÁвúÆ·Öжà¸ö¹Ø¼üºÍ¸ßÑϳÁÐÔ·ì϶£¬£¬£¬£¬£¬ÆäÖÐ×îÑϳÁµÄ·ì϶´æÔÚÓÚIBM Spectrum Protect¹¤¾ßÖÐ ¡£¡£¡£¡£¡£¡£¡£¡£IBM Spectrum Protect£¨Ç°³ÆTivoli Storage Manager£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×Êý¾Ý±£»£»£»£» £»£»¤Æ½Ì¨ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨ΪÆóÒµÌṩµ¥Ò»½ÚÔìºÍÖÎÀíµã£¬£¬£¬£¬£¬²¢Ö§³Ö¶ÔËùÓйæÄ£µÄÐé¹¹¡¢ÎïÀíºÍÔÆ»·¾³½øÐб¸·ÝºÍ¸´Ô­ ¡£¡£¡£¡£¡£¡£¡£¡£¶à¸ö·ì϶ÈçÏ£º


CVE-2019-4087

IBM Spectrum Protect ServersºÍStorage AgentsÖдæÔÚ»º³åÇøÃýÎó·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÖ´ÐÐÕýÈ·µÄÌìǵ¼ì²â ¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢Ëͳ¬³¤µÄÒªÇóÀûÓø÷ì϶ÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë»òÔì³É·þÎñÆ÷»òStorage Agents±ÀÀ£ ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-4088

IBM Spectrum Protect ServersºÍStorage AgentsÖдæÔÚ°²È«·ì϶ ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄ¿âÀûÓø÷ì϶»ñÈ¡ÌáÉýµÄȨÏÞ ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-4140

IBM Spectrum ProtectÖдæÔÚ°²È«·ì϶ ¡£¡£¡£¡£¡£¡£¡£¡£±¾µØ¹¥»÷Õß¿ÉÀûÓø÷ì϶¸´Ô­¾ÉÊý¾ÝÀ´´úÌæÏÖÓеÄÊý¾Ý¿â ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-4129

IBM Spectrum Protect Operations CenterÖдæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬¸Ã¸Ã·ì϶ԴÓÚÃýÎóÐÂÎÅÖÐÔ̺¬ÓÐÕ»¹ì¼£ ¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Operations Center¿ò¼ÜµÄ¾ßÌåÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-4292

IBM Security GuardiumÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×ÌṩÊý¾Ý±£»£»£»£» £»£»¤Ö°Äܵį½Ì¨ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ãƽ̨Ô̺¬×Ô½ç˵UI¡¢»ã±¨ÖÎÀíºÍÁ÷Ïß»¯µÄÉó¼ÆÁ÷³Ì¹¹½¨µÈÖ°ÄÜ ¡£¡£¡£¡£¡£¡£¡£¡£IBM Security GuardiumÖдæÔÚ°²È«·ì϶ ¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÉÏ´«ËÁÒâÎļþ£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-4134

IBM Planning AnalyticsÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×ÒµÎñ¹æ»®·ÖÎö½â¾ö¹æ»® ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹æ»®Ö§³Ö×Ô¶¯»¯Ö´ÐÐÒµÎñ¹æ»®¡¢Ô¤ËãºÍ·ÖÎöµÈÁ÷³Ì ¡£¡£¡£¡£¡£¡£¡£¡£IBM Planning AnalyticsÖдæÔÚ¿çÕ¾¾ç±¾·ì϶ ¡£¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚWeb UIÖÐ×¢ÈëËÁÒâµÄJavaScript´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£


CVE-2019-4260

IBM Daeja ViewONE VirtualÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»¿î»ùÓÚHTML5µÄÎĵµºÍͼÏñ²é¿´Æ÷ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·ÖØÒªÓÃÓڲ鿴¡¢×¢½âºÍ´òӡͼÏñºÍÎĵµ ¡£¡£¡£¡£¡£¡£¡£¡£IBM Daeja ViewONE VirtualÖдæÔÚ°²È«·ì϶ ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÏÂÔØËÁÒâ·þÎñÆ÷Îļþ ¡£¡£¡£¡£¡£¡£¡£¡£



·ì϶ÑéÖ¤



ÔÝÎÞPOC/EXP ¡£¡£¡£¡£¡£¡£¡£¡£



½¨¸´½¨Òé



Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó ¡£¡£¡£¡£¡£¡£¡£¡£



²Î¿¼Á´½Ó



https://www-01.ibm.com/support/docview.wss?uid=ibm10882472
https://www-01.ibm.com/support/docview.wss?uid=ibm10883346
https://www-01.ibm.com/support/docview.wss?uid=ibm10883236
https://www-01.ibm.com/support/docview.wss?uid=ibm10888279
https://www-01.ibm.com/support/docview.wss?uid=ibm10886607
https://www-01.ibm.com/support/docview.wss?uid=ibm10884382