vRealize Operations for Horizon Adapter °²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-24·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-3943£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.0£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3944£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.6£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3945£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.3£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
vRealize Operations for Horizon Adapter <= 6.6.0
vRealize Operations for Horizon Adapter <= 6.7.0
·ì϶¸ÅÊö
VMware vRealize Suite ÊÇרΪ»ìºÏÔÆ¶ø¹¹½¨µÄÔÆÖÎÀíÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£¡£VMware Horizon ÊÇÓÉ vmware ¹«Ë¾ÍƳöµÄÒ»¿îÕë¶ÔWindows¡¢Linux¼°Mac OS X£¬£¬£¬£¬£¬Ëù¿ª·¢µÄÐé¹¹×ÀÃæÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬vmware ¹Ù·½°ä²¼Á˱àºÅΪ VMSA-2020-0003 µÄ°²È«¸üС£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬ÑϳÁ·ì϶CVE-2020-3943¡¢¸ßΣ·ì϶CVE-2020-3944ºÍÖÐΣ·ì϶CVE-2020-3945£¬£¬£¬£¬£¬¸ÅÊöÈçÏ£º
CVE-2020-3943
¸Ã·ì϶³Ê´Ë¿Ì vRealize ×é¼þÔÚʵÏÖºÍ Horizon ×é¼þ½øÐкÏ×÷µÄʱ³½£¬£¬£¬£¬£¬¸ÃºÏ×÷·¨Ê½ÆôÓÃÁ˲»°²È«µÄ JMX RMI ·þÎñ£¬£¬£¬£¬£¬½ø¶øµ¼ÖÂËÁÒâ´úÂëÖ´Ðзì϶µÄ³öÏÖ¡£¡£¡£¡£¡£¡£¡£¡£
JMX£¨Java Management Extensions£¬£¬£¬£¬£¬¼´JavaÖÎÀíÀ©´ó£©ÊÇJavaƽ̨ÉÏΪÀûÓ÷¨Ê½¡¢É豸¡¢ÏµÍ³µÈÖ²ÈëÖÎÀíÖ°ÄܵĿò¼Ü¡£¡£¡£¡£¡£¡£¡£¡£JMXÄܹ»ÓâԽһϵÁÐÒì¹¹²Ù×÷ϵͳƽ̨¡¢ÏµÍ³ÏµÍ³½á¹¹ºÍÍøÂç´«ÊäºÍ̸£¬£¬£¬£¬£¬½Ã½ÝµÄ¿ª·¢Î޷켯³ÉµÄϵͳ¡¢ÍøÂçºÍ·þÎñÖÎÀíµ±Óᣡ£¡£¡£¡£¡£¡£¡£
CVE-2020-3944
vRealize Operations for Horizon AdapterÓµÓв»ÕýÈ·µÄÐÅÀµ´æ´¢ÅäÖ㬣¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2020-3945
¸Ã·ì϶µÄÔÒòÊÇHorizonÊÊÅäÆ÷µÄvRealize²Ù×÷ÓëHorizonÊÓͼ֮¼äµÄÅä¶ÔʵÏÖ²»ÕýÈ·£¬£¬£¬£¬£¬µ¼ÖÂÐÅϢй©¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬Çë¸üÐÂÖÁ6.6.1ºÍ6.7.1£¬£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://www.vmware.com/security/advisories/VMSA-2020-0003.html¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0003.html


¾©¹«Íø°²±¸11010802024551ºÅ