IBM API ConnectÑÏÖØÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-05

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-4202£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º10

CVE±àºÅ£ºCVE-2019-4203£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾¼°²úÆ·


IBM API Connect 5.0.0.0°æ±¾ÖÁ5.0.8.6°æ±¾


Îó²î¸ÅÊö


IBM API Connect£¨APIConnect£©ÊÇÃÀ¹úIBM¹«Ë¾µÄÒ»Ì×ÓÃÓÚÖÎÀíAPIÉúÃüÖÜÆÚµÄ¼¯³É½â¾ö¼Æ»®¡£¸Ã²úÆ·Ö§³Ö½¨Éè¡¢ÔËÐС¢ÖÎÀíºÍ±£»¤APIºÍ΢·þÎñµÈ¡£ÊÇÐí¶à½ðÈÚ»ú¹¹ÓÃÀ´Ö§³ÖPSD2»®¶¨µÄ¿ª·ÅÒøÐзþÎñ²úÆ·¡£


F-SecureÑо¿Ö°Ô±·¢Ã÷IBM API ConnectÖб£´æÁ½¸öÑÏÖØÎó²î£º


CVE-2019-4202

ÏÂÁî×¢ÈëÎó²î£¬¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨ÏÂÁî¡£


CVE-2019-4203

ÍâµØÎļþ°üÀ¨Îó²î£¬¹¥»÷Õ߿ɽèÖúDeveloper PortalʹÓøÃÎó²îÏÂÔØÖ÷»ú²Ù×÷ϵͳÉϵÄí§ÒâÎļþ²¢¿ÉÄÜʵÑé·þÎñÆ÷¶ËÇëÇóαÔì¹¥»÷¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£º
https://www-01.ibm.com/support/docview.wss?uid=ibm10880109

https://www-01.ibm.com/support/docview.wss?uid=ibm10880569


²Î¿¼Á´½Ó


https://www-01.ibm.com/support/docview.wss?uid=ibm10880109
https://www-01.ibm.com/support/docview.wss?uid=ibm10880569