CVE-2020-4703 | Spectrum Protect PlusËÁÒâ´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-09-160x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò |
IBM Spectrum Protect Plus | CVE-2020-4703 | ËÁÒâ´úÂëÖ´ÐÐ | ¸ßΣ | ÊÇ | 10.1.0-10.1.6°æ±¾ |
IBM Spectrum Protect PlusÊÇÓÃÓÚÐé¹¹»·¾³µÄÊý¾Ý±£»£»£»£»£»£»¤ºÍ¿ÉÓÃÐÔ½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚ¼¸·ÖÖÓÄÚʵÏÖ²¿Ê𣬣¬£¬£¬£¬£¬£¬²¢ÔÚÒ»Ó×ʱÄÚΪ»·¾³Ìṩ±£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£Ëü½«Êý¾Ý±£»£»£»£»£»£»¤»¯·±Îª¼ò£¬£¬£¬£¬£¬£¬£¬ÎÞÂÛÊÇ´æ´¢ÔÚÎïÀí»·¾³¡¢Ðé¹¹»·¾³¡¢Èí¼þ½ç˵µÄ»·¾³»¹ÊÇÔÆ»·¾³ÖеÄÊý¾Ý¶¼ÊÇÈç´Ë¡£¡£¡£¡£¡£¡£Ëü¿É×÷Ϊ¶ÀÁ¢½â¾ö¹æ»®À´Ö´ÐУ¬£¬£¬£¬£¬£¬£¬»òÕßÓë IBM Spectrum Protect »·¾³¼¯³É£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´ó¹æÄ£¸ßÐ§×ªÒÆ¸±±¾ÓÃÓڳ־ô洢ºÍÊý¾Ý¼à¹Ü¡£¡£¡£¡£¡£¡£
2020Äê9ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬IBM¹Ù·½°ä²¼ÆäSpectrum Protect PlusµÄÖÎÀí½ÚÔį̀ÖдæÔÚÒ»¸öµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-4703£©£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÓÉÓÚ6ÔÂÅû¶µÄÒ»¸ö¸ßΣ·ì϶CVE-2020-4470µÄ½¨¸´²»ÆëÈ«Ôì³ÉµÄ¡£¡£¡£¡£¡£¡£ÆäCVSSÆÀ·ÖΪ8¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé
CVE-2020-4470ÊÇIBM Spectrum Protect Plus 10.1.0µ½10.1.5°æ±¾ÖдæÔÚµÄÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»ÉÏ´«ËÁÒâÎļþµ½Ò×Êܹ¥»÷µÄ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£CVE-2020-4770·ì϶ÀûÓñØÒªÁ½¸ö²½Öè¡£¡£¡£¡£¡£¡£
µÚÒ»²½ÊÇͨ¹ýÏòURL¶Ëµãhttps://<spp_host>:8090/api/plugin·¢ËÍHTTP POSTÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬½«¶ñÒâµÄRPMÈí¼þ°üÉÏ´«µ½ÖÎÀíÔ¹ØÊ»§¿ÉдµÄĿ¼ÖС£¡£¡£¡£¡£¡£
µÚ¶þ²½ÊÇͨ¹ýÏòURL¶Ëµãhttp://<spp_host>:8090/emi/api/hotfix·¢ËÍHTTP POSTÐÂÎÅÀ´×°ÖöñÒâRPM°ü¡£¡£¡£¡£¡£¡£
ÔÚÒ×Êܹ¥»÷µÄ·þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬Á½¸ö²½Öè¶¼²»±ØÒªÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£CVE-2020-4470µÄ½¨¸´·¨Ê½½öͨ¹ý¶Ô/emi/api/hotfix¶ËµãÇ¿ÔìÖ´ÐÐÉí·ÝÑéÖ¤À´½â¾öµÚ¶þ¸ö²½Öè¡£¡£¡£¡£¡£¡£ËüÒÀÈ»ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþÉÏ´«µ½ÖÎÀíÔ¹ØÊ»§¿ÉдµÄĿ¼²¢ÔÚ¸ÃĿ¼ÏÂÔËÐС£¡£¡£¡£¡£¡£Õâµ¼Ö¶ñÒâ¹¥»÷Õß¿ÉÓëCVE-2020-4711·ì϶½áºÏʹÓ㬣¬£¬£¬£¬£¬£¬½«ÈκÎÎļþÉÏ´«µ½·þÎñÆ÷µÄËÁÒâĿ¼£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄRCE¡£¡£¡£¡£¡£¡£
¸Ã·ì϶µÄPoCÈçÏ£º
±¾´ÎIBM»¹½¨¸´ÁËSpectrum Protect PlusµÄÒ»¸öĿ¼±éÀú·ì϶£¨CVE-2020-4711£©¡£¡£¡£¡£¡£¡£
CVE-2020-4711ÊÇSpectrum Protect PlusµÄ¾ç±¾/opt/ECX/tools/scripts/restore_wrapper.shÖеÄÒ»¸öĿ¼±éÀú·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚĿ¼õè¾¶µÄ²é³±»Èƹý¡£¡£¡£¡£¡£¡£
δ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòURL¶Ëµãhttps://<spp_host>:8090/catalogmanager/api/catalog·¢ËÍÌØÔìµÄHTTPÒªÇóÀ´ÀûÓôËÎÊÌ⣬£¬£¬£¬£¬£¬£¬µ±cmode²ÎÊýΪrestorefromjobʱ£¬£¬£¬£¬£¬£¬£¬²»±ØÒªÉí·ÝÑéÖ¤£º
¶Ëµã´¦Ö÷¨Ê½Å²ÓÃcom.catalogic.ecx.catalogmanager.domain.CatalogManagerServiceImpl.restoreFromJob²½Ö裬£¬£¬£¬£¬£¬£¬¶øÎÞÐè²é³Óû§Í´´¦¡£¡£¡£¡£¡£¡£restoreFromJob²½ÖèÒÔrootÓû§Éí·ÝÖ´ÐÐ/opt/ECX/tools/scripts/restore_wrapper.sh¾ç±¾£¬£¬£¬£¬£¬£¬£¬½«¹¥»÷Õß½ÚÔìµÄHTTP²ÎÊýctarget / cRestoreTarget´«µÝ¸ø¸Ã¾ç±¾£º
Õâʹ¹¥»÷ÕßÄܹ»Í¨¹ýõè¾¶±éÀúÖ´ÐÐchmod -R 777£º
0x02 ´ëÖý¨Òé
Ŀǰ£¬£¬£¬£¬£¬£¬£¬IBM¹Ù·½ÒѾ°ä²¼Ò»Ê±¶©Õý°æ±¾£¬£¬£¬£¬£¬£¬£¬½¨Ò龡¿ì½øÐа²È«¸üС£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó¼°×°ÖÃ×¢Ã÷£º
https://www.ibm.com/support/pages/node/6254732
0x03 ÓйØÐÂÎÅ
https://threatpost.com/rce-exploit-ibm-data-risk-manager-no-patch/154986/
0x04 ²Î¿¼Á´½Ó
https://www.ibm.com/support/pages/node/6328867
https://www.tenable.com/cve/CVE-2020-4470
https://zh-cn.tenable.com/security/research/tra-2020-54?tns_redirect=true
0x05 ¹¦·òÏß
2020-09-14 IBM°ä²¼·ì϶²¼¸æ
2020-09-16 VSRC°ä²¼°²È«¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ