¡¾Îó²îͨ¸æ¡¿IBM WebSphere Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-36038)
Ðû²¼Ê±¼ä 2025-07-03Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | IBM WebSphere Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-36038 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-07-03 |
Îó²îÆÀ·Ö | 9.0 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | ¸ß | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
IBM WebSphereÊÇIBMÌṩµÄÒ»ÌׯóÒµ¼¶ÖÐÐļþƽ̨£¬£¬£¬Ö÷ÒªÓÃÓÚ¹¹½¨¡¢°²ÅźÍÖÎÀí»ùÓÚJavaµÄÓ¦ÓóÌÐò¡£¡£¡£¡£Æä½¹µã×é¼þWebSphere Application Server£¨WAS£©Ö§³ÖJEE±ê×¼£¬£¬£¬¾ß±¸¸ß¿ÉÓÃÐÔ¡¢¿ÉÀ©Õ¹ÐÔºÍÇå¾²ÐÔ£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ½ðÈÚ¡¢µçÐÅ¡¢Õþ¸®µÈÒªº¦ÐÐÒµµÄÆóÒµ¼¶ÏµÍ³ÖС£¡£¡£¡£
2025Äê7ÔÂ3ÈÕ£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½IBM WebSphere Application Server±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬Ôµ¹ÊÔÓÉÊÇϵͳ¶Ô²»ÊÜÐÅÈÎÊý¾Ý·´ÐòÁл¯´¦Öóͷ£²»µ±¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹Ìض¨ÐòÁл¯¹¤¾ß£¬£¬£¬ÔÚÎÞÐèÈÏÖ¤ºÍÓû§½»»¥µÄÇéÐÎÏÂÔ¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬½ø¶øÍêÈ«¿ØÖÆÊÜÓ°Ïìϵͳ¡£¡£¡£¡£¹¥»÷ÖØÆ¯ºó¸ßµ«Ò»µ©ÀֳɿÉÔì³ÉÑÏÖØÐ§¹û¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
½¨ÒéÓû§ÓÅÏÈͨ¹ý×°ÖÃÓÃÓÚÐÞ¸´APAR PH66674µÄInterim Fix²¹¶¡À´ÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£ÔÚ´Ë֮ǰ£¬£¬£¬Ó¦ÏȽ«IBM WebSphere Application ServerÉý¼¶ÖÁËùÐèµÄ×îµÍFix Pack°æ±¾£¬£¬£¬ÊÊÓÃÓÚ8.5.0.0ÖÁ8.5.5.27ºÍ9.0.0.0ÖÁ9.0.5.24°æ±¾µÄÓû§¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://www.ibm.com/support/pages/node/7237824/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ