Ãë¾àÁ¡ID |
22144 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Oracle 9i Application ¼¹öÀÇ WEB-INF µð·ºÅ丮´Â ¾×¼¼½º °¡´ÉÇÏ°Ô µÇ¾î ÀÖ´Ù. Oracle 9i Application Server (9iAS)´Â Oracle »ç¿¡ ÀÇÇØ ¹èÆ÷µÈ À¥ ¾îÇø®ÄÉÀÌ¼Ç ¼¹öÀÇ ±âº» ¼³ºñÀÌ´Ù. WEB-INF µð·ºÅ丮¸¦ °¡Áø Oracle 9iAS¿¡´Â ¹®Á¦Á¡ÀÌ Á¸ÀçÇÏ´Â °ÍÀ¸·Î º¸°íµÇ¾î ÀÖ´Ù. ¾î¶² Á¶°Ç ¾Æ·¡¿¡¼ ±× ¹®Á¦Á¡Àº ¿ø°ÝÁöÀÇ »ç¿ëÀÚ°¡ WEB-INF µð·ºÅ丮ÀÇ ³»¿ëµéÀ» ¾×¼¼½º ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. À̸¦ ÅëÇØ ¿ø°ÝÁöÀÇ »ç¿ëÀÚ´Â À¥ ¾îÇø®ÄÉÀ̼ǵéÀÇ ¼Ò½ºÄڵ带 ¾×¼¼½ºÇϰųª Áß¿äÇÑ ÀڷḦ °¡Á®°¥ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: Oracle 9i Application Server 1.0.2.2 Oracle 9i Application Server Release 2 9.0.2.0.0 Oracle 9i Application Server Release 2 9.0.2.0.1 |
ÇØ°áÃ¥ |
ÀÌ Ãë¾àÁ¡¿¡ ´ëÇØ¼´Â ´ÙÀ½°ú °°ÀÌ ¸ÞÀÎ httpd.conf ÆÄÀÏ¿¡ ´ÙÀ½ ¿£Æ®¸®¸¦ Ãß°¡ÇÏ¿© ¸ðµç WEB-INF µð·ºÅ丮µé¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Â÷´ÜÇÏ¿©¾ß ÇÑ´Ù.
<DirectoryMatch WEB-INF> Order deny,allow Deny from all </DirectoryMatch>
ÀÌ Ãë¾àÁ¡Àº ´ÙÀ½ Oracle Security Alert #47¿¡ ÀÖµíÀÌ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® À©µµ¿ìÁî NT¿ëÀ¸·Î Oracle 9i Application Server ¹öÀü 9.0.2.0.1, ±×¸®°í À¯´Ð½º ¿ëÀ¸·Î Oracle 9i Application Server 9.0.3¿¡¼ ¼öÁ¤µÈ °ÍÀ¸·Î º¸°íµÇ¾ú´Ù. À¥ »çÀÌÆ®¿¡¼´Â ¼öÁ¤µÈ ¹öÀüÀ» ´Ù¿î·Îµå ÇÒ ¼ö ¾øÀ¸¹Ç·Î º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¼öÁ¤µÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
6461 (SecurityFocus) |
°ü·Ã URL |
10930 (ISS) |
|