ManageEngine Applications Manager Ô¶³Ì´úÂëÖ´ÐÐÎó²î £¨CVE-2018-7890£©
2018-03-15
×ÛÊö
¿ËÈÕ£¬Ñо¿Ö°Ô±Í¨Ì«¹ýÎö·¢Ã÷ManageEngine Applications ManagerÖб£´æÒ»¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£Îó²îÔ´ÓڿɹûÕæ»á¼ûµÄtestCredential.do¶Ëµã£¬ÔÚÑéÖ¤Óû§ÌṩµÄƾ֤ʱ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÏÖÔÚ¹Ù·½»¹Ã»ÓÐÐû²¼Ð°汾¾ÙÐÐÐÞ¸´¡£
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7890
https://www.securityfocus.com/bid/103358
https://pentest.blog/advisory-manageengine-applications-manager-remote-code-execution-sqli-and/
Îó²î¸ÅÊö
testCredential.doÕâ¸ö¶Ëµã»á½ÓÊܶà¸öÓû§ÊäÈ룬²¢Í¨¹ý»á¼ûÖ¸¶¨µÄϵͳÀ´ÑéÖ¤ÌṩµÄƾ֤¡£ ¸Ã¶ËµãËæºó»áŲÓöà¸öÄÚ²¿À࣬ȻºóÖ´ÐÐÒ»¸öPowerShell¾ç±¾¡£ ÈôÊÇÖ¸¶¨µÄϵͳÊÇOfficeSharePointServer£¬Ôò´«¸ø´Ë¾ç±¾µÄÓû§ÃûºÍÃÜÂë²ÎÊý»áʧЧ£¬´Ó¶øÒý·¢Ç±ÔÚµÄÏÂÁî×¢È룬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
Îó²îÓ°Ïì
ÓÉÓÚApplications Manager´ó¶¼ÓÃÔÚÄÚÍøÇéÐÎÏ£¬Ö±½Ó±»Ê¹ÓõĹæÄ£½ÏС£¬¿ÉÊÇ£¬ÓÉÓÚ¸ÃÎó²îÓÐÀο¿µÄÇëÇóµØµã£¬µ±¹¥»÷ÕßÈëÇÖ½øÈëÆóÒµÄÚ²¿ÍøÂçºó£¬¿Éͨ¹ýɨÃèµÄ·½·¨Ì½²âºÍ·¢Ã÷£¬´Ó¶ø¾ÙÐÐʹÓ㬿ØÖƱ£´æÎó²îµÄ·þÎñÆ÷¡£
ÊÜÓ°ÏìµÄ°æ±¾
- ManageEngine Applications Manager 13.5
½â¾ö¼Æ»®
Ñо¿Ö°Ô±ÒѾ¹ûÕæÁËexploit¾ç±¾£¬ÒÀ¸½Èçme
ͬʱ£¬ÇëÊÜÓ°ÏìµÄÓû§¶ÔManageEngine¹Ù·½¼á³Ö¹Ø×¢£¬ÒÔ±ãËæÊ±¸üоÙÐÐÐÞ¸´¡£
²Î¿¼Á´½Ó£º
https://www.manageengine.com/products/applications_manager/download.html
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





