¡¾Îó²îͨ¸æ¡¿IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î(CVE-2024-51450)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î

CVE   ID

CVE-2024-51450

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


IBM Security Verify DirectoryÊÇÒ»¿îÆóÒµ¼¶Éí·ÝºÍ»á¼ûÖÎÃ÷È·¾ö¼Æ»® £¬£¬ÌṩÇå¾²µÄÓû§Éí·ÝÖÎÀíºÍĿ¼ЧÀÍ £¬£¬Ö§³ÖÖØ´óµÄÈÏÖ¤ºÍÊÚȨÐèÇó £¬£¬×ÊÖú×éÖ¯±£»£»£»£»£»£»¤Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£IBM Security Verify Access ApplianceÊÇÒ»¿îÓÃÓÚÖÎÀíÆóÒµÓ¦ÓóÌÐò»á¼ûµÄ½â¾ö¼Æ»® £¬£¬ÌṩÉí·ÝÑéÖ¤¡¢µ¥µãµÇ¼¡¢È¨ÏÞ¿ØÖƺͶàÒòËØÈÏÖ¤¹¦Ð§¡£¡£¡£ ¡£¡£Á½Õßͨ¹ý¼¯ÖÐÖÎÀíÓû§»á¼ûȨÏÞºÍÇå¾²Õ½ÂÔ £¬£¬È·±£ÆóÒµÓ¦ÓõÄÇå¾²ÐÔÓëºÏ¹æÐÔ £¬£¬ÆÕ±éÓ¦ÓÃÓÚÌáÉý×éÖ¯µÄÍøÂçÇå¾²ÐÔºÍÓû§ÖÎÀíЧÂÊ¡£¡£¡£ ¡£¡£


2025Äê2ÔÂ11ÈÕ £¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½IBMÐû²¼Á˹ØÓÚCVE-2024-51450ºÍCVE-2024-49814Îó²îµÄÇ徲ͨ¸æ¡£¡£¡£ ¡£¡£IBMÇå¾²Ñé֤Ŀ¼£¨IBM Security Verify Directory£©ºÍÇå¾²ÑéÖ¤»á¼û×°±¸£¨IBM Security Verify Access Appliance£©±£´æÁ½¸öÑÏÖØÎó²î £¬£¬¿ÉÄܱ»¹¥»÷ÕßʹÓà £¬£¬µ¼ÖÂδÊÚȨ»á¼ûºÍÏÂÁîÖ´ÐС£¡£¡£ ¡£¡£CVE-2024-51450ÊÇÒ»¸öÔ¶³ÌÏÂÁî×¢ÈëÎó²î £¬£¬ÔÊÐíÔ¶³Ì¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÈ«ÐĽṹµÄÇëÇó £¬£¬ÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî £¬£¬CVSSÆÀ·ÖΪ9.1 £¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£ ¡£¡£CVE-2024-49814ÊÇÒ»¸öÍâµØÈ¨ÏÞÌáÉýÎó²î £¬£¬ÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý²»ÐëÒªµÄȨÏÞÖ´ÐвÙ×÷ £¬£¬´Ó¶ø»ñµÃ¸ü¸ßȨÏÞ £¬£¬¿ÉÄÜÍêÈ«¿ØÖÆÏµÍ³ £¬£¬CVSSÆÀ·ÖΪ7.8 £¬£¬Îó²î¼¶±ð¸ßΣ¡£¡£¡£ ¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


10.0.0<=IBM Security Verify Directory<=10.0.3


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÂÔØ²¢×°ÖÃIBM Security Verify Directory°æ±¾10.0.3.1ÒÔ½â¾öÏà¹ØÇå¾²ÎÊÌâ¡£¡£¡£ ¡£¡£

ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/pages/ibm-security-verify-directory-fix-level-10031-download-document/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£ ¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬ïÔ̭ϵͳÎó²î £¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£ ¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£ ¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£ ¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£ ¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£ ¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/7182558

https://nvd.nist.gov/vuln/detail/CVE-2024-51450
https://nvd.nist.gov/vuln/detail/CVE-2024-49814
https://securityonline.info/ibm-security-verify-directory-vulnerable-to-critical-security-flaw-cve-2024-51450-cvss-9-1/