参考:
https://testbnull.medium.com/hpe-system-insight-manager-sim-amf-deserialization-lead-to-rce-cve-2020-7200-d49a9cf143c0
https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c05350888
下载地址:
https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c05350888
看了testbnull的文章,
(没下载成功,暂时先不安装了)
参考:https://github.com/shadowsock5/notes/blob/master/Attacking-BlazeDS-CodeFusion.md
影响版本:
7.6
描述:
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.
url:
/simsearch/messagebroker/amfsecure
使用org.jgroups.blocks.ReplicatedTree
这个gadget。