IBM QRadar SIEMÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4888£©

°ä²¼¹¦·ò 2021-02-03

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-4888

ʱ  ¼ä

2021-02-03

Àà   ÐÍ

RCE

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

 

IBM QRadar Security Information and Event Management (SIEM) ÊÇIBM¹«Ë¾µÄÒ»Ì×±»¿í·ºÊ¹ÓõݲȫÖÇÄܱ£»£» £»£»£»£»£»£»¤×ʲúºÍÐÅÏ¢Ô¶Àë¸ß¼¶ÍþвµÄ½â¾ö¹æ»®¡£¡£ ¡£¡£¡£¡£¡£Ëü¿ÉÔ®ÊÖ°²È«ÍŶÓÕýÈ·¼ì²âÆóÒµÖеÄÍþв²¢»®·ÖÓÅÏȼ¶£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒ¿ÉÄÜÖÇÄܶ´²ì£¬£¬£¬£¬£¬ £¬£¬£¬Ô®ÊÖÍŶÓѸËÙ×ö³ö·´Ó³£¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÏ÷¼õÊÂÎñÔì³ÉµÄÓ°Ïì¡£¡£ ¡£¡£¡£¡£¡£

2021Äê01ÔÂ27ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬IBM°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬ £¬£¬£¬¹«¿ªÁËIBM QRadar SIEMÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-4888£©£¬£¬£¬£¬£¬ £¬£¬£¬ÆäCVSSv3ÆÀ·Ö8.8¡£¡£ ¡£¡£¡£¡£¡£

ÓÉÓÚJava·´ÐòÁл¯Ö°ÄܶÔÓû§ÌṩµÄÄÚÈݽøÐÐÁ˲»°²È«µÄ·´ÐòÁл¯£¬£¬£¬£¬£¬ £¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâµÄÐòÁл¯Java¶ÔÏóÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬ £¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£ ¡£¡£¡£¡£¡£Ä¿Ç°¸Ã·ì϶Òѱ»½¨¸´£¬£¬£¬£¬£¬ £¬£¬£¬µ«PoCÒÑÔÚGithubÉϹ«¿ª¡£¡£ ¡£¡£¡£¡£¡£

½ØÖ¹Ä¿Ç°£¬£¬£¬£¬£¬ £¬£¬£¬Í¨¹ýzoomeyeËÑË÷£¬£¬£¬£¬£¬ £¬£¬£¬È«Çò¹²É¢²¼1262292¸öÉ豸ºÍÍøÕ¾£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÖйúÉ¢²¼123429£¬£¬£¬£¬£¬ £¬£¬£¬Î»¾ÓµÚÈý¡£¡£ ¡£¡£¡£¡£¡£

image.png

 

Ó°ÏìÁìÓò

IBM QRadar SIEM 7.4.0 - 7.4.2 Patch 1

IBM QRadar SIEM 7.3.0 -7.3.3 Patch 7

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶Òѱ»½¨¸´£¬£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÉý¼¶ÖÁÈçϰ汾£º

QRadar/QRM/QVM 7.4.2 Patch 2

ÏÂÔØÁ´½Ó£º

https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.4.2-QRADAR-QRSIEM-20210120225428&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR

 

QRadar/QRM/QVM 7.3.3 Patch 7 IF 1

ÏÂÔØÁ´½Ó£º

https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+Vulnerability+Manager&release=All&platform=All&function=fixId&fixids=7.3.3-QRADAR-QRSIEM-20210120163940INT&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR

 

 

0x03 ²Î¿¼Á´½Ó

https://www.ibm.com/support/pages/node/6409306

https://nvd.nist.gov/vuln/detail/CVE-2020-4888

https://gist.githubusercontent.com/testanull/e9ba06d0c0c403402f6941fe2dbb868a/raw/7c86ee239ce6edbc8b2f1b3b253196af946f6905/CVE-2020-4888_poc.txt


0x04 ¹¦·òÏß

2021-01-27  IBM°ä²¼°²È«²¼¸æ

2021-02-03  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png