:::

【資安漏洞預警】[TLP CLEAR] 英特內|DreamMaker - SQL Injection
【Security Vulnerability Alert】[TLP CLEAR] Interinfo|DreamMaker - SQL Injection

公告類別:行政公告
發佈日期:2026/09/18 至 2027/03/18
點閱數:61

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202609-00000007

[內容說明]
【英特內|DreamMaker - SQL Injection】(CVE-2026-85540,CVSS:8.8) 已通過身分鑑別之遠端攻擊者可注入任意SQL指令讀取、修改及刪除資料庫內容。
【英特內|DreamMaker - Reflected Cross-site Scripting】(CVE-2026-85541,CVSS:5.4) 已通過身分鑑別之遠端攻擊者可利用惡意網站於使用者端瀏覽器執行任意JavaScript程式碼。 詳細漏洞說明請參閱「漏洞資訊」。

[影響平台]
Dreammaker

[建議措施]
【CVE-2026-85540】 使用 SQLBuilder 元件 針對自行開發的功能,資料庫查詢或異動功能時,建議統一使用系統既有的 SQLBuilder 元件進行 SQL 組合、參數處理及資料庫操作。 應避免直接將外部輸入資料、表單參數或 URL 參數以字串串接方式組成 SQL 指令,以降低因自行開發程式處理不當而產生SQL Injection(SQL 注入)弱點的風險。 透過 SQLBuilder 或其他具備參數化查詢機制的標準元件,可進一步強化輸入資料處理及 SQL 執行安全性,並降低應用程式受到惡意 SQL 指令注入攻擊的可能性,相關元件開發使用手冊可洽本公司客服系統。

【CVE-2026-85541】
解決方式一:限制或停用 baServer3 若系統已更新至 2026 年 4 月以後、2026年6月以前版本,即使目前仍使用 Java Composer 2.2,可先透過 WLIST 白名單機制(WhiteList)限制 jform、baServer3 的存取來源,避免未授權使用者直接存取相關功能,相關WLIST操作文件可洽本公司客服系統。 若目前系統並無開發、維護或管理上使用 baServer3 的需求,亦可直接將:servlet/baServer3.class 進行移置、停用或重新命名。此元件移除後,原則上不影響既有系統應用程式的正常執行,但將無法再透過該 Servlet 使用其相關管理或開發功能。

解決方式二:更新至 Java Composer Server 2.3 可透過以下網址確認目前伺服器端 Java Composer Server 的版本及更新日期,或者透過Java Composer啟動時顯示資訊判斷: http://server-ip/servlet/baServer3

[參考資料]
1. https://www.twcert.org.tw/tw/cp-132-11183-06a5e-1.html
Forwarded from Taiwan Computer Emergency Response Coordination Center Cybersecurity Information Alert TWCERTCC-200-202609-00000007

[Content Description]
【Interinfo|DreamMaker - SQL Injection】(CVE-2026-85540,CVSS:8.8) Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
【Interinfo|DreamMaker - Reflected Cross-site Scripting】(CVE-2026-85541,CVSS:5.4) Authenticated remote attackers can exploit malicious websites to execute arbitrary JavaScript code in users' browsers. For detailed vulnerability information, please refer to "Vulnerability Information".

[Affected Platforms]
Dreammaker

[Recommended Measures]
【CVE-2026-85540】 For self-developed functions using the SQLBuilder component, it is recommended to uniformly use the system's existing SQLBuilder component for SQL composition, parameter processing, and database operations when performing database queries or modifications. Directly concatenating external input data, form parameters, or URL parameters into SQL commands as strings should be avoided to reduce the risk of SQL Injection(SQL injection) vulnerabilities caused by improper handling in self-developed programs. Using SQLBuilder or other standard components with parameterized query mechanisms can further strengthen input data processing and SQL execution security, and reduce the possibility of applications being subject to malicious SQL command injection attacks. The relevant component development and usage manuals can be obtained through the company's customer service system.

【CVE-2026-85541】
Solution 1: Restrict or disable baServer3 If the system has been updated to a version after April 2026 and before June 2026, even if Java Composer 2.2 is still currently being used, the WLIST whitelist mechanism(WhiteList) can first be used to restrict the access sources of jform and baServer3 to prevent unauthorized users from directly accessing the relevant functions. The relevant WLIST operation documentation can be obtained through the company's customer service system. If there is currently no need to use baServer3 for system development, maintenance, or management, you can also directly move, disable, or rename: servlet/baServer3.class. After this component is removed, in principle, the normal operation of existing system applications will not be affected, but the related management or development functions can no longer be used through this Servlet.

Solution 2: Update to Java Composer Server 2.3 The current version and update date of Java Composer Server on the server side can be confirmed through the following URL, or determined through the information displayed when Java Composer is started: http://server-ip/servlet/baServer3

[References]
1. https://www.twcert.org.tw/tw/cp-132-11183-06a5e-1.html

相關附件

※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。

返回列表