English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22001
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í BEAÀÇ WebLogic Server ¹öÀü 6.0Àº °ø°ÝÀÚ°¡ À¥¼­¹ö»óÀÇ µð·ºÅ丮µéÀ» Ž»öÇØ º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â "%00", "%2E", "%2F", ȤÀº "%5c"¿Í °°Àº Ưº°ÇÑ ASCII Ç¥ÇöÀÌ µû¸£´Â URLÀ» ¿äûÇÔÀ¸·Î½á µðÆúÆ® ´ÙÅ¥¸àÆ®¸¦ ¿ìȸ, À¥ Æú´õÀÇ ³»¿ëµéÀ» º¼ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ¶ÇÇÑ ÀÌ °áÇÔÀ¸·Î ÀÌ¿ëÇÏ¿© JSP ÆÄÀϵéÀÇ ¼Ò½ºÄڵ峪 ´Ù¸¥ µ¿Àû ³»¿ëµéÀ» º¼ ¼ö ÀÖ´Ù.

Ãë¾àÇÑ Ç÷§Æû:
WebLogic Server 6.0
Windows: ¸ðµç ¹öÀü

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/2513
http://www.iss.net/security_center/static/6283.php
ÇØ°áÃ¥ WebLogicÀÇ ÃֽйöÀü (6.0 SP1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù. ÃֽйöÀüÀº http://www.oracle.com/technetwork/middleware/weblogic/overview/index.html ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)