McAfee Database Security 6Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-06-07

0x00 ©¶´¸ÅÊö

McAfee Êý¾Ý¿âÄþ¾²²úÎïÄܹ»ÊµÊ±±£»¤Òªº¦ÒµÎñµÄÊý¾Ý¿â£¬ÖÆÖ¹ÆäÔâÊÜÍⲿ¡¢ÄÚ²¿ºÍÊý¾Ý¿âÄÚ²¿µÄÖÖÖÖ¹¥»÷¡£

2021Äê06ÔÂ01ÈÕ£¬McAfeeÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËDatabase SecurityÖеÄ5¸öÄþ¾²Â©¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓÃÕâЩ©¶´Î´ÊÚȨ·ÃÎÊ¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢»ò¿ØÖÆ·þÎñÆ÷¡£

 

0x01 ©¶´ÏêÇé

image.png

±¾´ÎÐÞ¸´µÄ5¸ö©¶´ÖУ¬CVE-2021-23894ºÍCVE-2021-23895ÊÇMcAfee Database Security £¨DBSec£©Öеķ´ÐòÁл¯Â©¶´£¬Î´¾­ÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ¹¹½¨µÄJavaÐòÁл¯¹¤¾ßµ½DBSec·þÎñÆ÷À´´¥·¢´Ë©¶´£¬²¢Í¨¹ýÔÚDBSec·þÎñÆ÷ÉÏ´´½¨¾ßÓйÜÀíԱȨÏ޵ķ´ÏòshellÀ´¿ØÖÆ·þÎñÆ÷¡£

CVE-2021-31830ÊÇDBSecÖеÄXSS©¶´£¬ÓµÓйÜÀíȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ýÔÚÅäÖÃÒª¼à¿ØµÄÊý¾Ý¿âÃû³ÆÊ±Ç¶ÈëJavaScript´úÂ룬µ±ÈκÎÊÚȨÓû§µÇ¼µ½DBSec½çÃæ²¢´ò¿ª¸ÃÊý¾Ý¿âµÄÊôÐÔÅäÖÃÒ³ÃæÊ±£¬½«´¥·¢¶ñÒâ´úÂ룬µ«ÀûÓôË©¶´ÐèÒªÓû§½»»¥¡£

CVE-2021-31831ÊÇDBSecÖÐÒÑɾ³ý½Å±¾µÄ²»ÕýÈ··ÃÎÊ©¶´£¬ÕâЩ½Å±¾±»±£ÁôÏÂÀ´£¬ÒÔ±ãÔÚ½«À´ÐèÒª·ÖÎö¾ÉʼþʱʹÓᣵ«¾­¹ýÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýREST API»ñµÃ¶Ô¹ÜÀí¿ØÖÆÌ¨ÖÐÒѱê־Ϊɾ³ý»ò¹ýÆÚµÄÇ©ÃûSQL½Å±¾µÄ·ÃÎÊ£¬µ«ÀûÓôË©¶´ÐèÒªÓû§½»»¥¡£

CVE-2021-23896ÊÇDBSec¹ÜÀíÔ±½çÃæÖеÄÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«Êä©¶´£¬ÓµÓйÜÀíȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÀûÓôË©¶´¼ì²ìMcAfee Insights ServerµÄδ¼ÓÃÜÃÜÂ룬µ«ÀûÓôË©¶´ÐèÒªÓû§½»»¥¡£

 

CVE-ID

ÀàÐÍ

CVSSv3ÆÀ·Ö

Ó°Ï췶Χ

CVE-2021-23894

·´ÐòÁл¯

9.6

<   4.8.2

CVE-2021-23895

·´ÐòÁл¯

9.0

CVE-2021-23896

ÐÅϢй¶

3.2

CVE-2021-31830

XSS

5.9

CVE-2021-31831

·ÃÎÊ¿ØÖÆ´íÎó

4.9

 

 

0x02 ´¦Öý¨Òé

ĿǰMcAfeeÒѾ­ÔÚDBSec 4.8.2ÖÐÐÞ¸´ÁËÕâЩ©¶´£¬½¨Ò鼰ʱÉý¼¶¸üУº

ÏÂÔØÁ¬½Ó£º

https://www.mcafee.com/enterprise/en-us/downloads.html

 

0x03 ²Î¿¼Á´½Ó

https://kc.mcafee.com/corporate/index?page=content&id=SB10359#Remediation

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23894

https://nvd.nist.gov/vuln/detail/CVE-2021-23894

 

0x04 ʱ¼äÏß

2021-06-01  McAfeeÐû²¼Äþ¾²Í¨¸æ

2021-06-02  McAfee¸üÐÂÄþ¾²Í¨¸æ

2021-06-07  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png