{"id":2986,"date":"2020-03-09T00:26:22","date_gmt":"2020-03-09T00:26:22","guid":{"rendered":"http:\/\/www.manageengine.jp\/support\/kb\/Desktop_Central\/?p=2986"},"modified":"2023-05-11T21:31:28","modified_gmt":"2023-05-11T12:31:28","slug":"%e3%80%90cve-2020-1938%e3%80%91ghostcat%e3%81%b8%e3%81%ae%e5%af%be%e5%bf%9c%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6","status":"publish","type":"post","link":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/?p=2986","title":{"rendered":"\u3010\u4fee\u6b63\u6e08\u3011GhostCat(CVE-2020-1938)\u3078\u306e\u5bfe\u5fdc\u306b\u3064\u3044\u3066"},"content":{"rendered":"<div class=\"attention\">\n    \u3053\u306e\u8a18\u4e8b\u3067\u306f\u3001Destkop Central\u3067\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3068\u3057\u3066\u4f7f\u7528\u3057\u3066\u3044\u308bTomcat\u306e\u8106\u5f31\u6027(CVE-2020-1938)\u3078\u306e\u5bfe\u5fdc\u65b9\u6cd5\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002\u7ba1\u7406\u5bfe\u8c61\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u306b\u5bfe\u3057\u3066\u306e\u5bfe\u5fdc\u65b9\u6cd5\u306f\u4ee5\u4e0b\u306e<a href=\"#point\">\u30dd\u30a4\u30f3\u30c8<\/a>\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002\n<\/div>\n<h5>\u3010\u5bfe\u8c61\u30d3\u30eb\u30c9\u3011<\/h5>\n<p>Desktop Central 10.0.477\u4ee5\u524d<\/p>\n<h5>\u3010\u554f\u984c\u3011<\/h5>\n<p>CVE-2020-1938 \"GhostCat\"\u306b\u3064\u3044\u3066\u306e\u8a73\u7d30\u306f\u4ee5\u4e0b\u306e\u30ea\u30f3\u30af\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/www.jpcert.or.jp\/at\/2020\/at200009.html\" target=\"_blank\" rel=\"noopener\">Apache Tomcat \u306e\u8106\u5f31\u6027 (CVE-2020-1938) \u306b\u95a2\u3059\u308b\u6ce8\u610f\u559a\u8d77<\/a>(JPCERT\/CC)<\/li>\n<li><a href=\"https:\/\/www.ipa.go.jp\/archive\/security\/security-alert\/2019\/alert20200225.html\" target=\"_blank\" rel=\"noopener\">Apache Tomcat \u306b\u304a\u3051\u308b\u8106\u5f31\u6027\uff08CVE-2020-1938\uff09\u306b\u3064\u3044\u3066<\/a>(IPA)<\/li>\n<li><a href=\"https:\/\/lists.apache.org\/thread.html\/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E\" target=\"_blank\" rel=\"noopener\">[SECURITY] CVE-2020-1938 AJP Request Injection and potential Remote Code Execution<\/a>(Apache Software Foundation)<\/li>\n<\/ul>\n<h5>\u3010\u5bfe\u51e6\u65b9\u6cd5\u3011<\/h5>\n<p>Desktop Central\u3092\u6700\u65b0\u306e10.0.479\u3078\u30d0\u30fc\u30b8\u30e7\u30f3\u30a2\u30c3\u30d7\u3057\u307e\u3059\u3002<br \/>\n\u30d0\u30fc\u30b8\u30e7\u30f3\u30a2\u30c3\u30d7\u524d\u5f8c\u306e\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u306e\u53d6\u5f97\u306a\u3069\u3001\u8a73\u7d30\u306a\u624b\u9806\u306b\u3064\u304d\u307e\u3057\u3066\u306f\u3001<a href=\"http:\/\/www.manageengine.jp\/support\/kb\/Desktop_Central\/?p=2994\">\u30d0\u30fc\u30b8\u30e7\u30f3\u30a2\u30c3\u30d7\u624b\u9806\u306b\u95a2\u3059\u308b\u30ca\u30ec\u30c3\u30b8<\/a>\u3092\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\u3002<br \/>\n<a name=\"point\"><\/a><\/p>\n<div class=\"point\">\n    <strong>\u7ba1\u7406\u5bfe\u8c61Linux\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u306b\u304a\u3051\u308bGhostcat\u3078\u306e\u5bfe\u5fdc<\/strong><br \/>\n    Desktop Central \/ Patch Manager Plus\u3067\u306f\u3001Linux\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf\u30fc\u306b\u5bfe\u3059\u308bTomcat\u306e\u30d1\u30c3\u30c1\u7ba1\u7406\u3092\u30b5\u30dd\u30fc\u30c8\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/www.manageengine.jp\/products\/Desktop_Central\/patch_management_supported_application.html\" target=\"_blank\" rel=\"noopener\">Destkop Central\u306e\u30d1\u30c3\u30c1\u7ba1\u7406\u6a5f\u80fd\u5bfe\u5fdc\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3\u88fd\u54c1\u4e00\u89a7<\/a><\/li>\n<li><a href=\"https:\/\/www.manageengine.jp\/products\/Patch_Manager_Plus\/supported-applications.html\" target=\"_blank\" rel=\"noopener\">Patch Manager Plus\u306e\u30d1\u30c3\u30c1\u7ba1\u7406\u6a5f\u80fd\u5bfe\u5fdc\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3\u88fd\u54c1\u4e00\u89a7<\/a><\/li>\n<\/ul>\n<p>    \u5404\u30c7\u30a3\u30b9\u30c8\u30ea\u30d3\u30e5\u30fc\u30b7\u30e7\u30f3\u306e\u30ea\u30dd\u30b8\u30c8\u30ea(apt\/yum\u7b49)\u306b\u6700\u65b0\u306eTomcat\u304c\u8ffd\u52a0\u3055\u308c\u6b21\u7b2c\u3001\u6700\u5c0f\u9650\u306e\u78ba\u8a8d\u3092\u884c\u3063\u305f\u3046\u3048\u3067\u30be\u30fc\u30db\u30fc\u30b3\u30fc\u30dd\u30ec\u30fc\u30b7\u30e7\u30f3\u304c\u30d1\u30c3\u30c1DB\u306b\u60c5\u5831\u3092\u8ffd\u52a0\u3057\u307e\u3059(\u53c2\u8003: <a href=\"https:\/\/blogs.manageengine.jp\/dc_patch_architecture\/\" target=\"_blank\" rel=\"noopener\">Desktop Central\u306e\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3<\/a>)\u3002\u30d1\u30c3\u30c1\u60c5\u5831\u304c\u8ffd\u52a0\u3055\u308c\u6b21\u7b2c\u3001\u30d1\u30c3\u30c1DB\u306e\u540c\u671f(\u66f4\u65b0)\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u3054\u5229\u7528\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\n    \u30d1\u30c3\u30c1DB\u306e\u624b\u52d5\u540c\u671f(\u66f4\u65b0): \u300c\u30d1\u30c3\u30c1\u7ba1\u7406\u300d\u30bf\u30d6 &gt; \u66f4\u65b0 &gt; \u66f4\u65b0 \u3092\u30af\u30ea\u30c3\u30af<br \/>\n    &nbsp; (\u53c2\u8003: <a href=\"https:\/\/www.manageengine.jp\/support\/kb\/Desktop_Central\/?p=2255\" target=\"_blank\" rel=\"noopener\">\u30d1\u30c3\u30c1DB\u306e\u540c\u671f(\u66f4\u65b0)<\/a>)<br \/>\n    \u6700\u65b0\u306e\u30d1\u30c3\u30c1\u60c5\u5831\u306e\u78ba\u8a8d: \u300c\u30d1\u30c3\u30c1\u7ba1\u7406\u300d\u30bf\u30d6 &gt; \u300c\u6700\u65b0\u306e\u30d1\u30c3\u30c1\u300d &gt; \u5fc5\u8981\u306b\u5fdc\u3058\u3066\u30d5\u30a3\u30eb\u30bf\u30fc\u6761\u4ef6\u3084\u53f3\u4e0a\u306e\u691c\u7d22\u30a2\u30a4\u30b3\u30f3\u304b\u3089\u6761\u4ef6\u3092\u6307\u5b9a<br \/>\n    &nbsp; (\u53c2\u8003: <a href=\"https:\/\/www.manageengine.jp\/support\/kb\/Desktop_Central\/?p=1392\" target=\"_blank\" rel=\"noopener\">\u30d1\u30c3\u30c1\u306e\u5206\u985e<\/a>)<br \/>\n    \u203b\u4e00\u822c\u306b\u3001\u30d1\u30c3\u30c1\u306e\u9069\u7528\u306b\u5f53\u305f\u3063\u3066\u306f\u3001\u304a\u5ba2\u69d8\u3054\u81ea\u8eab\u3067\u3054\u691c\u8a3c\u304f\u3060\u3055\u3044\u3002\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u3053\u306e\u8a18\u4e8b\u3067\u306f\u3001Destkop Central\u3067\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u3068\u3057\u3066\u4f7f\u7528\u3057\u3066\u3044\u308bTomcat\u306e\u8106\u5f31\u6027(CVE-2020-1938)\u3078\u306e\u5bfe\u5fdc\u65b9\u6cd5\u306b\u3064\u3044\u3066\u8aac\u2026 <a href=\"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/?p=2986\" class=\"more\">\uff3b\u7d9a\u304d\u3092\u8aad\u3080\uff3d<\/a><\/p>\n","protected":false},"author":72,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[436],"tags":[467,465,47,433,114,466],"class_list":["post-2986","post","type-post","status-publish","format-standard","hentry","category-08security","tag-ghostcat","tag-tomcat","tag-47","tag-433","tag-114","tag-466"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=\/wp\/v2\/posts\/2986","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=\/wp\/v2\/users\/72"}],"replies":[{"embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2986"}],"version-history":[{"count":10,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=\/wp\/v2\/posts\/2986\/revisions"}],"predecessor-version":[{"id":8233,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=\/wp\/v2\/posts\/2986\/revisions\/8233"}],"wp:attachment":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2986"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2986"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Endpoint_Central\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2986"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}