IBM DataRisk Manager |¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-23

0x00 ·ì϶¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

IBM Data Risk Manager

ÔÝÎÞ

AB

ÑϳÁ

ÊÇ

IBM Data Risk Manager 2.0.1 to 2.0.3

IBM Data Risk Manager 2.0.4 to 2.0.6 ¿ÉÄÜÊÜÓ°Ïì

ÔÝÎÞ

CI

ÑϳÁ

ÊÇ

ÔÝÎÞ

IDP

ÑϳÁ

ÊÇ

ÔÝÎÞ

AFD

¸ßΣ

ÊÇ


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


AgileÐÅÏ¢°²È«¹«Ë¾µÄ×êÑÐÈËÔ±Pedro Ribeiro 4ÔÂ21ÈÕÔÚGitHubÉϹ«¿ªÅû¶ÁËËĸöIBM 0day·ì϶¡£¡£¡£¡£¡£ÕâЩ·ì϶ӰÏìIBM DataRisk Manager£¨IDRM£©£¬ £¬£¬£¬£¬IDRMÊÇÒ»¿îÆóÒµ°²È«¹¤¾ß£¬ £¬£¬£¬£¬¾ÛºÏÀ´×Ô·ì϶ɨÃ蹤¾ßºÍÆäËû·çÏÕÖÎÀí¹¤¾ßµÄÐÅÏ¢£¬ £¬£¬£¬£¬ÒÔ±ãÖÎÀíÔ±µ÷²é°²È«ÎÊÌâ¡£¡£¡£¡£¡£

ÔÚ·ÖÎöIDRM LinuxÐé¹¹É豸ʱ£¬ £¬£¬£¬£¬Ribeiro·¢ÏÖÁË4¸ö0day£ºÉí·ÝÈÏÖ¤ÃýÎó·ì϶¡¢ºÅÁî×¢Èë·ì϶¡¢²»°²È«µÄĬÈÏÃÜÂë·ì϶ÒÔ¼°ËÁÒâÎļþÏÂÔØ·ì϶¡£¡£¡£¡£¡£ÕâЩ·ì϶Äܹ»µ¥¶ÀʹÓÃÒ²Äܹ»×éºÏʹÓ㬠£¬£¬£¬£¬×éºÏʹÓÃǰÈý¸ö·ì϶Äܹ»Ê¹¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬 £¬£¬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸö·ì϶Äܹ»Ê¹Î´ÊÚȨµÄ¹¥»÷ÕßÏÂÔØËÁÒâÎļþ¡£¡£¡£¡£¡£

·ì϶µÄÅû¶ÕßRibeiro°µÊ¾£¬ £¬£¬£¬£¬IDRMÊÇ´¦ÖÃÃô¸ÐÐÅÏ¢µÄÆóÒµ°²È«²úÆ·£¬ £¬£¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑϳÁÊÜË𣬠£¬£¬£¬£¬Òò¶øÔÚIBM»Ø¾ø½ÓÊÜ·ì϶»ã±¨ºóÑ¡Ôñ½«Æä°ä²¼³öÀ´¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬IBM¹«Ë¾½¨¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄËÁÒâÎļþÏÂÔØ·ì϶ºÍºÅÁî×¢Èë·ì϶£¬ £¬£¬£¬£¬²¢ÇÒÔÚµ÷²éÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¡£¡£

£¨1£©Éí·ÝÈÏÖ¤ÃýÎó·ì϶ԴÓÚIDRMÔÚ/ albatross / saml / idpSelectionÓÐÒ»¸öAPI½«¹¥»÷ÕßÌṩµÄIDÓëϵͳÉϵÄÓÐЧÓû§ÓйØÁª¡£¡£¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶³ÁÖÃÈκÎÒÑÓÐÕË»§ÃÜÂ룬 £¬£¬£¬£¬Ô̺¬ÖÎÀíÔ±ÃÜÂë¡£¡£¡£¡£¡£

£¨2£©ºÅÁî×¢Èë·ì϶ԴÓÚIDRMµÄ/albatross/restAPI/v2/nmap/run/scanÖеÄij¸öAPIÔÊÐíÓû§Ê¹ÓÃnmap¾ç±¾Ö´ÐÐÍøÂçɨÃ裬 £¬£¬£¬£¬ÈôÊǸþ籾ÎļþÓɹ¥»÷ÕßÉÏ´«£¬ £¬£¬£¬£¬ÄÇô¾Í¿ÉÄܱ»¸½¼Ó¶ñÒâºÅÁî¡£¡£¡£¡£¡£

£¨3£©Ä¬ÈÏÃÜÂë·ì϶²úÉúµÄÔ­ÒòÔÚÓÚIDRMÐé¹¹É豸ÖеÄÖÎÀíÓû§ÊÇ¡°a3user¡±£¬ £¬£¬£¬£¬Ä¬ÈÏÃÜÂëΪ¡°idrm¡±¡£¡£¡£¡£¡£¸ÃÓû§±»ÔÊÐíͨ¹ýSSHµÇ¼ºÍÔËÐÐsudoºÅÁî¡£¡£¡£¡£¡£¹ÌÈ»IDRMÇ¿Ôìweb½Ó¿ÚµÄÖÎÀíÔ±Óû§£¨¡°admin¡±£©ÔÚ³õ´ÎµÇ¼ʱÅú¸ÄÃÜÂ룬 £¬£¬£¬£¬µ«ÊÇȴûÓÐÒªÇó¡°a3user¡±Óû§Åú¸ÄÃÜÂë¡£¡£¡£¡£¡£

£¨4£©ËÁÒâÎļþÏÂÔØ·ì϶ԴÓÚ/albatross/eurekaservice/fetchLogFilesÖеÄij¸öAPIÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§´ÓϵͳÏÂÔØÈÕÖ¾Îļþ¡£¡£¡£¡£¡£µ«ÊÇ£¬ £¬£¬£¬£¬logFileNameList²ÎÊýÔ̺¬Ò»¸öĿ¼±éÀú·ì϶£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶´ÓϵͳÏÂÔØËÁÒâÎļþ¡£¡£¡£¡£¡£


0x02 ´ëÖý¨Òé


ºÅÁî×¢Èë·ì϶ºÍËÁÒâÎļþÏÂÔØ·ì϶Òѽ¨¸´£¬ £¬£¬£¬£¬½«IDRMÉý¼¶µ½2.0.4°æ±¾¼´¿É¡£¡£¡£¡£¡£ÏÂÔØµØÖ·£ºhttps://www.ibm.com/software/passportadvantage/pacustomers.html£»£»£»£»£»

ĬÈÏÃÜÂë·ì϶£¬ £¬£¬£¬£¬IBM½¨Ò鯾¾Ý°ä²¼µÄ×°ÖÃÖ¸ÄÏÔÚ³õ´Î×°ÖÃʱ³ÁÖᣡ£¡£¡£¡£²Î¿¼Á´½Ó£ºhttps://www.ibm.com/support/knowledgecenter/en/SSJQ6V_2.0.6/com.ibm.idrm.doc/install/tsk/tsk_installguide_idrm_configuration.html£»£»£»£»£»

Éí·ÝÈÏÖ¤ÃýÎó·ì϶ÁÙʱûÓн¨¸´£¬ £¬£¬£¬£¬Çëʵʱ¹Ø×¢³§ÉÌÐÅÏ¢£ºhttps://www.ibm.com/support/pages/node/6195705¡£¡£¡£¡£¡£


0x03 ÓйØÐÂÎÅ


https://www.zdnet.com/article/security-researcher-discloses-four-ibm-zero-days-after-company-refused-to-patch/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://github.com/pedrib/PoC/blob/master/advisories/IBM/ibm_drm/ibm_drm_rce.md


0x05 ¹¦·òÏß


2020-04-21 GitHub°ä²¼·ì϶

2020-04-23 VSRC°ä²¼·ì϶¹«¸æ



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website