¡¾Îó²îͨ¸æ¡¿IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î(CVE-2024-51450)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

IBM Security Verify DirectoryÏÂÁîÖ´ÐÐÎó²î

CVE   ID

CVE-2024-51450

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


IBM Security Verify DirectoryÊÇÒ»¿îÆóÒµ¼¶Éí·ÝºÍ»á¼ûÖÎÃ÷È·¾ö¼Æ»®£¬£¬£¬ÌṩÇå¾²µÄÓû§Éí·ÝÖÎÀíºÍĿ¼ЧÀÍ£¬£¬£¬Ö§³ÖÖØ´óµÄÈÏÖ¤ºÍÊÚȨÐèÇ󣬣¬£¬×ÊÖú×éÖ¯±£»£»£»¤Ãô¸ÐÊý¾Ý¡£¡£¡£IBM Security Verify Access ApplianceÊÇÒ»¿îÓÃÓÚÖÎÀíÆóÒµÓ¦ÓóÌÐò»á¼ûµÄ½â¾ö¼Æ»®£¬£¬£¬ÌṩÉí·ÝÑéÖ¤¡¢µ¥µãµÇ¼¡¢È¨ÏÞ¿ØÖƺͶàÒòËØÈÏÖ¤¹¦Ð§¡£¡£¡£Á½Õßͨ¹ý¼¯ÖÐÖÎÀíÓû§»á¼ûȨÏÞºÍÇå¾²Õ½ÂÔ£¬£¬£¬È·±£ÆóÒµÓ¦ÓõÄÇå¾²ÐÔÓëºÏ¹æÐÔ£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÌáÉý×éÖ¯µÄÍøÂçÇå¾²ÐÔºÍÓû§ÖÎÀíЧÂÊ¡£¡£¡£


2025Äê2ÔÂ11ÈÕ£¬£¬£¬¿­Ê±K66¼¯ÍÅVSRC¼à²âµ½IBMÐû²¼Á˹ØÓÚCVE-2024-51450ºÍCVE-2024-49814Îó²îµÄÇ徲ͨ¸æ¡£¡£¡£IBMÇå¾²Ñé֤Ŀ¼£¨IBM Security Verify Directory£©ºÍÇå¾²ÑéÖ¤»á¼û×°±¸£¨IBM Security Verify Access Appliance£©±£´æÁ½¸öÑÏÖØÎó²î£¬£¬£¬¿ÉÄܱ»¹¥»÷ÕßʹÓ㬣¬£¬µ¼ÖÂδÊÚȨ»á¼ûºÍÏÂÁîÖ´ÐС£¡£¡£CVE-2024-51450ÊÇÒ»¸öÔ¶³ÌÏÂÁî×¢ÈëÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬣¬£¬ÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬CVSSÆÀ·ÖΪ9.1£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£CVE-2024-49814ÊÇÒ»¸öÍâµØÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬ÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Í¨¹ý²»ÐëÒªµÄȨÏÞÖ´ÐвÙ×÷£¬£¬£¬´Ó¶ø»ñµÃ¸ü¸ßȨÏÞ£¬£¬£¬¿ÉÄÜÍêÈ«¿ØÖÆÏµÍ³£¬£¬£¬CVSSÆÀ·ÖΪ7.8£¬£¬£¬Îó²î¼¶±ð¸ßΣ¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


10.0.0<=IBM Security Verify Directory<=10.0.3


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÂÔØ²¢×°ÖÃIBM Security Verify Directory°æ±¾10.0.3.1ÒÔ½â¾öÏà¹ØÇå¾²ÎÊÌâ¡£¡£¡£

ÏÂÔØÁ´½Ó£º
https://www.ibm.com/support/pages/ibm-security-verify-directory-fix-level-10031-download-document/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.ibm.com/support/pages/node/7182558

https://nvd.nist.gov/vuln/detail/CVE-2024-51450
https://nvd.nist.gov/vuln/detail/CVE-2024-49814
https://securityonline.info/ibm-security-verify-directory-vulnerable-to-critical-security-flaw-cve-2024-51450-cvss-9-1/