Ãë¾àÁ¡ID |
22231 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Oracle 9iAS Portal demo ÆäÀÌÁöµé(PORTAL_DEMO.ORG_CHART)Àº mod_plsql¸¦ ÅëÇØ ¾×¼¼½º°¡ °¡´ÉÇÏ´Ù. ÀÌ ÆäÀÌÁöµéÀº ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ°¡ ¾î¶² URLÀ» ÅëÇÏ¿© µ¥ÀÌÅͺ£À̽º ÁúÀǵ鿡 ¾ÇÀÇÀûÀÎ SQL ¹®¹ýÀ» »ðÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. OracleÀÇ RDBMS´Â PL/SQLÀ» ÀÌ¿ëÇÏ¿© ÀúÀåµÈ ÆÐŰÁö¿Í ÇÁ·Î½ÃÁ®µéÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ ÆÐŰÁö¿Í ÇÁ·Î½ÃÁ®µéÀº Oracle Application ServerÀÇ Portal ¸ðµâÀ» ÅëÇÏ¿© ¾×¼¼½ºµÉ ¼ö ÀÖ´Ù. Oracle Application Server´Â Oracle ¾îÇø®ÄÉÀ̼ǵéÀ» À§ÇØ ´ÙÁöÀÎµÈ À¥ ¼¹öÀÌ´Ù. ¸¹Àº PL/SQL ÆÐŰÁö¿Í ÇÁ·Î½ÃÁ®µéÀº SQL Injection¿¡ Ãë¾àÇÏ´Ù. Oracle9i Application ServerÀÇ Portal ¸±¸®Áî 1 ¹öÀü 3.0.9.8.5 ÀÌÇϵé°ú Portal Release 2 ¹öÀü 9.0.2.3.0 ÀÌÇϵéÀº "List of Values" (LOVs), Portal DB Provider Forms, Portal DB Provider Hierarchy, ±×¸®°í Portal DB Provider XML ±¸¼º¿ä¼Òµé¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ SQL Injection¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â ÀÓÀÇÀÇ SQL Äڵ带 Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á »ç¿ëÀÚ µ¥ÀÌÅÍ¿¡ ´ëÇÑ Àΰ¡µÇÁö ¾ÊÀº ¾×¼¼½º¸¦ ÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ Oracle9i Application Server¿¡ ÀÖ´Â »ç¿ëÀÚ µ¥ÀÌÅ͸¦ Ãß°¡, ¼öÁ¤, ȤÀº »èÁ¦ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.oracle.com/technetwork/topics/security/2003alert61-128865.pdf http://www.securiteam.com/securitynews/6C0021P8UQ.html http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0032.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle9i Application Server Portal Release 1, v3.0.9.8.5 ÀÌÇÏ Oracle9i Application Server Portal Release 2, v9.0.2.3.0 ÀÌÇÏ Windows Any version Unix Any version Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Oracle Security Alert #61À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.oracle.com/technetwork/topics/security/2003alert61-128865.pdf
Oracle »ç´Â Portal Release 1 ¹öÀü 3.0.9.8.5À» À§ÇÑ ÆÐÄ¡ 3068980¿Í Portal Release 2 ¹öÀü 9.0.2.3.0À» À§ÇÑ ÆÐÄ¡ 2852895¸¦ ¸±¸®Áî ÇÏ¿´´Ù. »ç¿ëÀÚµéÀº OracleÀÇ http://metalink.oracle.com ¿¡ ÀÖ´Â metalink·ÎºÎÅÍ ÆÐÄ¡µéÀ» ´Ù¿î·Îµå ÇÒ ¼ö ÀÖ´Ù.
-- ȤÀº --
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î PORTAL_DEMO ½ºÅ°¸¶¿¡ ÀÖ´Â PL/SQL ÆÐŰÁö·ÎºÎÅÍ Public grant¸¦ À§ÇÑ Execute¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù. (REVOKE execute ON portal_demo.org_chart FROM public;) |
°ü·Ã URL |
CVE-2003-1193 (CVE) |
°ü·Ã URL |
8966 (SecurityFocus) |
°ü·Ã URL |
13593 (ISS) |
|