IBM DataRisk Manager |¶à¸ö°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-230x00 ·ì϶¸ÅÊö
|
²úÆ· |
CVE ID |
Àà ÐÍ |
·ì϶µÈ¼¶ |
Ô¶³ÌÀûÓà |
Ó°ÏìÁìÓò |
|
IBM Data Risk Manager |
ÔÝÎÞ |
AB |
ÑϳÁ |
ÊÇ |
IBM Data Risk Manager 2.0.1 to 2.0.3 IBM Data Risk Manager 2.0.4 to 2.0.6 ¿ÉÄÜÊÜÓ°Ïì |
|
ÔÝÎÞ |
CI |
ÑϳÁ |
ÊÇ |
||
|
ÔÝÎÞ |
IDP |
ÑϳÁ |
ÊÇ |
||
|
ÔÝÎÞ |
AFD |
¸ßΣ |
ÊÇ |
0x01 ·ì϶ÏêÇé
AgileÐÅÏ¢°²È«¹«Ë¾µÄ×êÑÐÈËÔ±Pedro Ribeiro 4ÔÂ21ÈÕÔÚGitHubÉϹ«¿ªÅû¶ÁËËĸöIBM 0day·ì϶¡£¡£¡£¡£¡£ÕâЩ·ì϶ӰÏìIBM DataRisk Manager£¨IDRM£©£¬£¬£¬£¬£¬IDRMÊÇÒ»¿îÆóÒµ°²È«¹¤¾ß£¬£¬£¬£¬£¬¾ÛºÏÀ´×Ô·ì϶ɨÃ蹤¾ßºÍÆäËû·çÏÕÖÎÀí¹¤¾ßµÄÐÅÏ¢£¬£¬£¬£¬£¬ÒÔ±ãÖÎÀíÔ±µ÷²é°²È«ÎÊÌâ¡£¡£¡£¡£¡£
ÔÚ·ÖÎöIDRM LinuxÐé¹¹É豸ʱ£¬£¬£¬£¬£¬Ribeiro·¢ÏÖÁË4¸ö0day£ºÉí·ÝÈÏÖ¤ÃýÎó·ì϶¡¢ºÅÁî×¢Èë·ì϶¡¢²»°²È«µÄĬÈÏÃÜÂë·ì϶ÒÔ¼°ËÁÒâÎļþÏÂÔØ·ì϶¡£¡£¡£¡£¡£ÕâЩ·ì϶Äܹ»µ¥¶ÀʹÓÃÒ²Äܹ»×éºÏʹÓ㬣¬£¬£¬£¬×éºÏʹÓÃǰÈý¸ö·ì϶Äܹ»Ê¹¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸö·ì϶Äܹ»Ê¹Î´ÊÚȨµÄ¹¥»÷ÕßÏÂÔØËÁÒâÎļþ¡£¡£¡£¡£¡£
·ì϶µÄÅû¶ÕßRibeiro°µÊ¾£¬£¬£¬£¬£¬IDRMÊÇ´¦ÖÃÃô¸ÐÐÅÏ¢µÄÆóÒµ°²È«²úÆ·£¬£¬£¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑϳÁÊÜË𣬣¬£¬£¬£¬Òò¶øÔÚIBM»Ø¾ø½ÓÊÜ·ì϶»ã±¨ºóÑ¡Ôñ½«Æä°ä²¼³öÀ´¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬IBM¹«Ë¾½¨¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄËÁÒâÎļþÏÂÔØ·ì϶ºÍºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬²¢ÇÒÔÚµ÷²éÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¡£¡£
£¨1£©Éí·ÝÈÏÖ¤ÃýÎó·ì϶ԴÓÚIDRMÔÚ/ albatross / saml / idpSelectionÓÐÒ»¸öAPI½«¹¥»÷ÕßÌṩµÄIDÓëϵͳÉϵÄÓÐЧÓû§ÓйØÁª¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶³ÁÖÃÈκÎÒÑÓÐÕË»§ÃÜÂ룬£¬£¬£¬£¬Ô̺¬ÖÎÀíÔ±ÃÜÂë¡£¡£¡£¡£¡£
£¨2£©ºÅÁî×¢Èë·ì϶ԴÓÚIDRMµÄ/albatross/restAPI/v2/nmap/run/scanÖеÄij¸öAPIÔÊÐíÓû§Ê¹ÓÃnmap¾ç±¾Ö´ÐÐÍøÂçɨÃ裬£¬£¬£¬£¬ÈôÊǸþ籾ÎļþÓɹ¥»÷ÕßÉÏ´«£¬£¬£¬£¬£¬ÄÇô¾Í¿ÉÄܱ»¸½¼Ó¶ñÒâºÅÁî¡£¡£¡£¡£¡£
£¨3£©Ä¬ÈÏÃÜÂë·ì϶²úÉúµÄÔÒòÔÚÓÚIDRMÐé¹¹É豸ÖеÄÖÎÀíÓû§ÊÇ¡°a3user¡±£¬£¬£¬£¬£¬Ä¬ÈÏÃÜÂëΪ¡°idrm¡±¡£¡£¡£¡£¡£¸ÃÓû§±»ÔÊÐíͨ¹ýSSHµÇ¼ºÍÔËÐÐsudoºÅÁî¡£¡£¡£¡£¡£¹ÌÈ»IDRMÇ¿Ôìweb½Ó¿ÚµÄÖÎÀíÔ±Óû§£¨¡°admin¡±£©ÔÚ³õ´ÎµÇ¼ʱÅú¸ÄÃÜÂ룬£¬£¬£¬£¬µ«ÊÇȴûÓÐÒªÇó¡°a3user¡±Óû§Åú¸ÄÃÜÂë¡£¡£¡£¡£¡£
£¨4£©ËÁÒâÎļþÏÂÔØ·ì϶ԴÓÚ/albatross/eurekaservice/fetchLogFilesÖеÄij¸öAPIÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄÓû§´ÓϵͳÏÂÔØÈÕÖ¾Îļþ¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬logFileNameList²ÎÊýÔ̺¬Ò»¸öĿ¼±éÀú·ì϶£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶´ÓϵͳÏÂÔØËÁÒâÎļþ¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
ºÅÁî×¢Èë·ì϶ºÍËÁÒâÎļþÏÂÔØ·ì϶Òѽ¨¸´£¬£¬£¬£¬£¬½«IDRMÉý¼¶µ½2.0.4°æ±¾¼´¿É¡£¡£¡£¡£¡£ÏÂÔØµØÖ·£ºhttps://www.ibm.com/software/passportadvantage/pacustomers.html£»£»£»£»£»
ĬÈÏÃÜÂë·ì϶£¬£¬£¬£¬£¬IBM½¨Ò鯾¾Ý°ä²¼µÄ×°ÖÃÖ¸ÄÏÔÚ³õ´Î×°ÖÃʱ³ÁÖᣡ£¡£¡£¡£²Î¿¼Á´½Ó£ºhttps://www.ibm.com/support/knowledgecenter/en/SSJQ6V_2.0.6/com.ibm.idrm.doc/install/tsk/tsk_installguide_idrm_configuration.html£»£»£»£»£»
Éí·ÝÈÏÖ¤ÃýÎó·ì϶ÁÙʱûÓн¨¸´£¬£¬£¬£¬£¬Çëʵʱ¹Ø×¢³§ÉÌÐÅÏ¢£ºhttps://www.ibm.com/support/pages/node/6195705¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.zdnet.com/article/security-researcher-discloses-four-ibm-zero-days-after-company-refused-to-patch/#ftag=RSSbaffb68
0x04 ²Î¿¼Á´½Ó
https://github.com/pedrib/PoC/blob/master/advisories/IBM/ibm_drm/ibm_drm_rce.md
0x05 ¹¦·òÏß
2020-04-21 GitHub°ä²¼·ì϶
2020-04-23 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ