McAfee Database Security 6Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-06-07

0x00 ·ì϶¸ÅÊö

McAfee Êý¾Ý¿â°²È«²úÆ·¿ÉÄÜʵʱ±£»£»£»£»£»£»£»£»¤¹Ø¼üÒµÎñµÄÊý¾Ý¿â £¬£¬£¬£¬£¬Ô¤·ÀÆäÔâ·ê±í²¿¡¢ÄÚ²¿ºÍÊý¾Ý¿âÄÚ²¿µÄ¸÷À๥»÷¡£¡£ ¡£¡£¡£¡£

2021Äê06ÔÂ01ÈÕ £¬£¬£¬£¬£¬McAfee°ä²¼°²È«²¼¸æ £¬£¬£¬£¬£¬½¨¸´ÁËDatabase SecurityÖеÄ5¸ö°²È«·ì϶ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ì϶δÊÚȨ½Ó¼û¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½ÚÔì·þÎñÆ÷¡£¡£ ¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

image.png

±¾´Î½¨¸´µÄ5¸ö·ì϶ÖÐ £¬£¬£¬£¬£¬CVE-2021-23894ºÍCVE-2021-23895ÊÇMcAfee Database Security £¨DBSec£©Öеķ´ÐòÁл¯·ì϶ £¬£¬£¬£¬£¬Î´¾­ÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâ¹¹½¨µÄJavaÐòÁл¯¶ÔÏóµ½DBSec·þÎñÆ÷À´´¥·¢´Ë·ì϶ £¬£¬£¬£¬£¬²¢Í¨¹ýÔÚDBSec·þÎñÆ÷ÉÏ´´½¨ÓµÓÐÖÎÀíԱȨÏ޵ķ´ÏòshellÀ´½ÚÔì·þÎñÆ÷¡£¡£ ¡£¡£¡£¡£

CVE-2021-31830ÊÇDBSecÖеÄXSS·ì϶ £¬£¬£¬£¬£¬Õ¼ÓÐÖÎÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»Í¨¹ýÔÚÅäÖÃÒª¼à¿ØµÄÊý¾Ý¿âÃû³ÆÊ±Ç¶ÈëJavaScript´úÂë £¬£¬£¬£¬£¬µ±ÈκÎÊÚȨÓû§µÇ¼µ½DBSec½çÃæ²¢´ò¿ª¸ÃÊý¾Ý¿âµÄÊôÐÔÅäÖÃÒ³ÃæÊ± £¬£¬£¬£¬£¬½«´¥·¢¶ñÒâ´úÂë £¬£¬£¬£¬£¬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£¡£ ¡£¡£¡£¡£

CVE-2021-31831ÊÇDBSecÖÐÒÑɾ³ý¾ç±¾µÄ²»ÕýÈ·½Ó¼û·ì϶ £¬£¬£¬£¬£¬ÕâЩ¾ç±¾±»±£ÁôÏÂÀ´ £¬£¬£¬£¬£¬ÒÔ±ãÔÚ½«À´±ØÒª·ÖÎöÍùÊÂÎñʱʹÓᣡ£ ¡£¡£¡£¡£µ«¾­¹ýÈÏÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýREST API»ñµÃ¶ÔÖÎÀí½ÚÔį̀ÖÐÒÑÏóÕ÷Ϊɾ³ý»ò¹ýÆÚµÄÊðÃûSQL¾ç±¾µÄ½Ó¼û £¬£¬£¬£¬£¬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£¡£ ¡£¡£¡£¡£

CVE-2021-23896ÊÇDBSecÖÎÀíÔ±½çÃæÖеÄÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä·ì϶ £¬£¬£¬£¬£¬Õ¼ÓÐÖÎÀíȨÏ޵Ĺ¥»÷ÕßÄܹ»ÀûÓô˷ì϶²é¿´McAfee Insights ServerµÄδ¼ÓÃÜÃÜÂë £¬£¬£¬£¬£¬µ«ÀûÓô˷ì϶±ØÒªÓû§½»»¥¡£¡£ ¡£¡£¡£¡£

 

CVE-ID

ÀàÐÍ

CVSSv3ÆÀ·Ö

Ó°ÏìÁìÓò

CVE-2021-23894

·´ÐòÁл¯

9.6

<   4.8.2

CVE-2021-23895

·´ÐòÁл¯

9.0

CVE-2021-23896

ÐÅϢй¶

3.2

CVE-2021-31830

XSS

5.9

CVE-2021-31831

½Ó¼û½ÚÔìÃýÎó

4.9

 

 

0x02 ´ëÖý¨Òé

ĿǰMcAfeeÒѾ­ÔÚDBSec 4.8.2Öн¨¸´ÁËÕâЩ·ì϶ £¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üУº

ÏÂÔØÏνӣº

https://www.mcafee.com/enterprise/en-us/downloads.html

 

0x03 ²Î¿¼Á´½Ó

https://kc.mcafee.com/corporate/index?page=content&id=SB10359#Remediation

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23894

https://nvd.nist.gov/vuln/detail/CVE-2021-23894

 

0x04 ¹¦·òÏß

2021-06-01  McAfee°ä²¼°²È«²¼¸æ

2021-06-02  McAfee¸üа²È«²¼¸æ

2021-06-07  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png