Ãë¾àÁ¡ID |
22250 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Servlet |
»ó¼¼¼³¸í |
ÇØ´ç Novell Groupwise servlet ¼¹ö´Â µðÆúÆ® ÆÐ½º¿öµå¸¦ »ç¿ëÇϰí ÀÖ´Ù. Novell Groupwise Servlet Gateway´Â NetWare v1.1.7b ±×¸®°í NetWare Enterprise À¥ ¼¹ö¸¦ À§ÇÑ Novell JVM (Java Virtual Machine)ÀÌ´Ù. Novell GroupWise ¹öÀü 5.5 Enhancement Pack ±×¸®°í 6.0¿¡ ÀÖ´Â ¼ºí¸´(Servlet) °ü¸®ÀÚ´Â ¼ºí¸´ °ü¸®ÀÚ¸¦ À§ÇÑ µðÆúÆ® »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå·Î ¼³Ä¡µÇ¾î ÀÖ´Ù. ¼ºí¸´ °ü¸®ÀÚ´Â ¼ºí¸´µéÀÇ È¯°æ±¸¼ºÀ» žÀç(load), žÀç ÇØÁö, ÀçžÀç ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¼ºí¸´µéÀ» Á¦¾îÇϰí žÀç ÇØÁöÇÒ ¼ö ÀÖ´Â ´É·ÂÀº °ø°ÝÀÚ°¡ »ç¿ëÀڵ鿡 ´ëÇÑ À¥ ±â¹ÝÀÇ ¼ºñ½ºµéÀ» °ÅºÎÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â »ç¿ëÀÚµéÀÌ ¸ÞÀÏÀ̳ª ´Ù¸¥ ¼ºí¸´ ±â¹ÝÀÇ ÀÚ¿øµéÀ» ¾×¼¼½ºÇÒ ¼ö ¾ø°Ô ÇÑ´Ù.
µðÆúÆ® ÆÐ½º¿öµå°¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö¸¦ Å×½ºÆ®Çϱâ À§Çؼ´Â: https://[targethost]/servlet/ServletManager/
»ç¿ëÀÚ¿¡ 'servlet' ±×¸®°í ÆÐ½º¿öµå·Î´Â 'manager'¸¦ ÀÔ·ÂÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.securiteam.com/securitynews/6G00Q003FE.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Novell GroupWise 6.0 Novell GroupWise 5.5 Enhancement Pack Netware 5 Microsoft Windows Any version |
ÇØ°áÃ¥ |
µðÆúÆ® ÆÐ½º¿öµå¸¦ º¯°æÇÏ¿©¾ß ÇÑ´Ù.
1. SYS:\JAVA\SERVLETS\SERVLET.PROPERTIES ÆÄÀÏÀ» ¿ÀÇÂÇÑ´Ù. 2. ServletManager¸¦ À§ÇÑ ¼½¼Ç¿¡ ÀÖ´Â ´ÙÀ½ ¶óÀο¡ À§Ä¡ÇÑ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå¸¦ º¯°æÇÑ´Ù: servlet.ServletManager.initArgs=datamethod=POST,user=servlet,password=manager,bgcolor
ÀÚ¼¼ÇÑ Á¤º¸¸¦ ¿øÇÑ´Ù¸é Novell ±â¼ú Á¤º¸ ¹®¼ 10067329¸¦ Âü°íÇÑ´Ù: http://support.novell.com/cgi-bin/search/searchtid.cgi?/10067329.htm |
°ü·Ã URL |
CVE-2001-1195 (CVE) |
°ü·Ã URL |
3697 (SecurityFocus) |
°ü·Ã URL |
7701 (ISS) |
|