English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210025
À§Çèµµ 40
Æ÷Æ® 8080, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç JBoss Application ¼­¹ö´Â JMX Äֿܼ¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. JBoss Application Server (jbossas) 3.2.4¿¡¼­ 4.0.5 ±îÁöÀÇ ¹öÀüµéÀº ÆÄÀϵéÀ» ÀúÀå ȤÀº »èÁ¦Çϴµ¥ »ç¿ëÇϱâ Àü¿¡ JMX ConsoleÀÇ 'DeploymentFileRepository' ¼­ºñ½º¿¡ ÀÇÇØ »ç¿ëµÇ´Â BaseDir Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ°ª¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ µð·ºÅ丮µéÀ» Ž»öÇÏ¿© ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» Àаųª ¼öÁ¤ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â ¾îÇø®ÄÉÀ̼ÇÀÇ ±ÇÇÑÀ» °¡Áö°í Ãë¾àÇÑ ½Ã½ºÅÛÀ¸·ÎºÎÅÍ ÀÓÀÇÀÇ ÆÄÀϵ鿡 ´ëÇÑ Àбâ, »ý¼º, »èÁ¦ ¹× µ¤¾î¾²±â¸¦ ¼öÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://jira.jboss.com/jira/browse/JBAS-3861
https://community.jboss.org/wiki/securethejmxconsole
http://www.securityfocus.com/archive/1/archive/1/452830/100/0/threaded
http://securitytracker.com/alerts/2006/Nov/1017289.html
http://secunia.com/advisories/23095

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Jboss Application Server ¹öÀü 4.0.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ Wiki ±Û¿¡ ¼³¸íµÇ¾î ÀÖµíÀÌ JMX Console¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ÈÀüÇÏ°Ô ÇÏ¿©¾ß ÇÑ´Ù:
https://community.jboss.org/wiki/securethejmxconsole
°ü·Ã URL CVE-2006-5750 (CVE)
°ü·Ã URL 21219 (SecurityFocus)
°ü·Ã URL 30376 (ISS)