English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22144
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle 9i Application ¼­¹öÀÇ WEB-INF µð·ºÅ丮´Â ¾×¼¼½º °¡´ÉÇÏ°Ô µÇ¾î ÀÖ´Ù.
Oracle 9i Application Server (9iAS)´Â Oracle »ç¿¡ ÀÇÇØ ¹èÆ÷µÈ À¥ ¾îÇø®ÄÉÀÌ¼Ç ¼­¹öÀÇ ±âº» ¼³ºñÀÌ´Ù. WEB-INF µð·ºÅ丮¸¦ °¡Áø Oracle 9iAS¿¡´Â ¹®Á¦Á¡ÀÌ Á¸ÀçÇÏ´Â °ÍÀ¸·Î º¸°íµÇ¾î ÀÖ´Ù. ¾î¶² Á¶°Ç ¾Æ·¡¿¡¼­ ±× ¹®Á¦Á¡Àº ¿ø°ÝÁöÀÇ »ç¿ëÀÚ°¡ WEB-INF µð·ºÅ丮ÀÇ ³»¿ëµéÀ» ¾×¼¼½º ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. À̸¦ ÅëÇØ ¿ø°ÝÁöÀÇ »ç¿ëÀÚ´Â À¥ ¾îÇø®ÄÉÀ̼ǵéÀÇ ¼Ò½ºÄڵ带 ¾×¼¼½ºÇϰųª Áß¿äÇÑ ÀڷḦ °¡Á®°¥ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
Oracle 9i Application Server 1.0.2.2
Oracle 9i Application Server Release 2 9.0.2.0.0
Oracle 9i Application Server Release 2 9.0.2.0.1
ÇØ°áÃ¥ ÀÌ Ãë¾àÁ¡¿¡ ´ëÇØ¼­´Â ´ÙÀ½°ú °°ÀÌ ¸ÞÀÎ httpd.conf ÆÄÀÏ¿¡ ´ÙÀ½ ¿£Æ®¸®¸¦ Ãß°¡ÇÏ¿© ¸ðµç WEB-INF µð·ºÅ丮µé¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Â÷´ÜÇÏ¿©¾ß ÇÑ´Ù.

<DirectoryMatch WEB-INF>
Order deny,allow
Deny from all
</DirectoryMatch>

ÀÌ Ãë¾àÁ¡Àº ´ÙÀ½ Oracle Security Alert #47¿¡ ÀÖµíÀÌ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® À©µµ¿ìÁî NT¿ëÀ¸·Î Oracle 9i Application Server ¹öÀü 9.0.2.0.1, ±×¸®°í À¯´Ð½º ¿ëÀ¸·Î Oracle 9i Application Server 9.0.3¿¡¼­ ¼öÁ¤µÈ °ÍÀ¸·Î º¸°íµÇ¾ú´Ù. À¥ »çÀÌÆ®¿¡¼­´Â ¼öÁ¤µÈ ¹öÀüÀ» ´Ù¿î·Îµå ÇÒ ¼ö ¾øÀ¸¹Ç·Î º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¼öÁ¤µÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 6461 (SecurityFocus)
°ü·Ã URL 10930 (ISS)