{ "Name": "Websphere Portal SSRF", "Description": "

IBM WebSphere Portal consists of middleware, applications (called portlets), and development tools used to build and manage secure business-to-business (B2B), business-to-customer (B2C), and business-to-employee (B2E) portals.

IBM WebSphere Portal has server-side request forgery vulnerabilities, and attackers can use vulnerabilities to detect intranet to obtain sensitive information.

", "Product": "Websphere Portal", "Homepage": "https://www.ibm.com/", "DisclosureDate": "2021-12-01", "Author": "1291904552@qq.com", "FofaQuery": "body=\"/wps/contenthandler\" || body=\"Websphere Portal\" || body=\"/wps/portal/calligaris\"", "GobyQuery": "body=\"/wps/contenthandler\" || body=\"Websphere Portal\" || body=\"/wps/portal/calligaris\"", "Level": "1", "Impact": "

IBM WebSphere Portal has server-side request forgery vulnerabilities, and attackers can use vulnerabilities to detect intranet to obtain sensitive information.

", "Recommendation": "

The vendor has released a bug fix, please pay attention to the update in time: https://www.ibm.com/

1. Set access policies and whitelist access through security devices such as firewalls.

2.If not necessary, prohibit public network access to the system.

", "Translation": { "CN": { "Name": "Websphere Portal SSRF", "VulType": ["SSRF漏洞"], "Tags": ["SSRF漏洞"], "Description": "

IBM WebSphere Portal 由用于构建和管理安全的企业对企业(B2B)、企业对客户(B2C)和企业对雇员(B2E)门户网站的中间件、应用程序(称为 portlet)和开发工具组成。

IBM WebSphere Portal 存在服务端请求伪造漏洞,攻击者可利用漏洞探测内网获取敏感信息。

", "Impact": "

IBM WebSphere Portal 存在服务端请求伪造漏洞,攻击者可利用漏洞探测内网获取敏感信息。

", "Product": "Websphere Portal", "Recommendation": "

⼚商已发布了漏洞修复程序,请及时关注更新:https://www.ibm.com/

1、通过防⽕墙等安全设备设置访问策略,设置⽩名单访问。

2、如⾮必要,禁⽌公⽹访问该系统。

" }, "EN": { "Name": "Websphere Portal SSRF", "VulType": ["ssrf"], "Tags": ["ssrf"], "Description": "

IBM WebSphere Portal consists of middleware, applications (called portlets), and development tools used to build and manage secure business-to-business (B2B), business-to-customer (B2C), and business-to-employee (B2E) portals.

IBM WebSphere Portal has server-side request forgery vulnerabilities, and attackers can use vulnerabilities to detect intranet to obtain sensitive information.

", "Impact": "

IBM WebSphere Portal has server-side request forgery vulnerabilities, and attackers can use vulnerabilities to detect intranet to obtain sensitive information.

", "Product": "Websphere Portal", "Recommendation": "

The vendor has released a bug fix, please pay attention to the update in time: https://www.ibm.com/

1. Set access policies and whitelist access through security devices such as firewalls.

2.If not necessary, prohibit public network access to the system.

" } }, "References": [ "https://blog.assetnote.io/2021/12/25/advisory-websphere-portal/" ], "HasExp": true, "ExpParams": [ { "name": "dnslog", "type": "input", "value": "xxx.dnslog.cn" } ], "ExpTips": null, "ScanSteps": null, "Tags": [ "ssrf" ], "VulType": [ "ssrf" ], "CVEIDs": [ "" ], "CVSSScore": "6.0", "AttackSurfaces": { "Application": null, "Support": null, "Service": null, "System": null, "Hardware": null }, "CNNVD": [ "" ], "CNVD": [ "" ] }