English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22231
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle 9iAS Portal demo ÆäÀÌÁöµé(PORTAL_DEMO.ORG_CHART)Àº mod_plsql¸¦ ÅëÇØ ¾×¼¼½º°¡ °¡´ÉÇÏ´Ù. ÀÌ ÆäÀÌÁöµéÀº ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ°¡ ¾î¶² URLÀ» ÅëÇÏ¿© µ¥ÀÌÅͺ£À̽º ÁúÀǵ鿡 ¾ÇÀÇÀûÀÎ SQL ¹®¹ýÀ» »ðÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. OracleÀÇ RDBMS´Â PL/SQLÀ» ÀÌ¿ëÇÏ¿© ÀúÀåµÈ ÆÐŰÁö¿Í ÇÁ·Î½ÃÁ®µéÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ ÆÐŰÁö¿Í ÇÁ·Î½ÃÁ®µéÀº Oracle Application ServerÀÇ Portal ¸ðµâÀ» ÅëÇÏ¿© ¾×¼¼½ºµÉ ¼ö ÀÖ´Ù. Oracle Application Server´Â Oracle ¾îÇø®ÄÉÀ̼ǵéÀ» À§ÇØ ´ÙÁöÀÎµÈ À¥ ¼­¹öÀÌ´Ù. ¸¹Àº PL/SQL ÆÐŰÁö¿Í ÇÁ·Î½ÃÁ®µéÀº SQL Injection¿¡ Ãë¾àÇÏ´Ù.
Oracle9i Application ServerÀÇ Portal ¸±¸®Áî 1 ¹öÀü 3.0.9.8.5 ÀÌÇϵé°ú Portal Release 2 ¹öÀü 9.0.2.3.0 ÀÌÇϵéÀº "List of Values" (LOVs), Portal DB Provider Forms, Portal DB Provider Hierarchy, ±×¸®°í Portal DB Provider XML ±¸¼º¿ä¼Òµé¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ SQL Injection¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â ÀÓÀÇÀÇ SQL Äڵ带 Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á »ç¿ëÀÚ µ¥ÀÌÅÍ¿¡ ´ëÇÑ Àΰ¡µÇÁö ¾ÊÀº ¾×¼¼½º¸¦ ÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ Oracle9i Application Server¿¡ ÀÖ´Â »ç¿ëÀÚ µ¥ÀÌÅ͸¦ Ãß°¡, ¼öÁ¤, ȤÀº »èÁ¦ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.oracle.com/technetwork/topics/security/2003alert61-128865.pdf
http://www.securiteam.com/securitynews/6C0021P8UQ.html
http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0032.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle9i Application Server Portal Release 1, v3.0.9.8.5 ÀÌÇÏ
Oracle9i Application Server Portal Release 2, v9.0.2.3.0 ÀÌÇÏ
Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ Oracle Security Alert #61À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.oracle.com/technetwork/topics/security/2003alert61-128865.pdf

Oracle »ç´Â Portal Release 1 ¹öÀü 3.0.9.8.5À» À§ÇÑ ÆÐÄ¡ 3068980¿Í Portal Release 2 ¹öÀü 9.0.2.3.0À» À§ÇÑ ÆÐÄ¡ 2852895¸¦ ¸±¸®Áî ÇÏ¿´´Ù. »ç¿ëÀÚµéÀº OracleÀÇ http://metalink.oracle.com ¿¡ ÀÖ´Â metalink·ÎºÎÅÍ ÆÐÄ¡µéÀ» ´Ù¿î·Îµå ÇÒ ¼ö ÀÖ´Ù.

-- ȤÀº --

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î PORTAL_DEMO ½ºÅ°¸¶¿¡ ÀÖ´Â PL/SQL ÆÐŰÁö·ÎºÎÅÍ Public grant¸¦ À§ÇÑ Execute¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù. (REVOKE execute ON portal_demo.org_chart FROM public;)
°ü·Ã URL CVE-2003-1193 (CVE)
°ü·Ã URL 8966 (SecurityFocus)
°ü·Ã URL 13593 (ISS)