Ãë¾àÁ¡ID |
22495 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Servlet |
»ó¼¼¼³¸í |
ÇØ´ç Oracle WebLogic ¼¹ö´Â HTTP Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. new line °ú °°Àº ¿äû Çì´õÀÇ Æ¯¼ö¹®ÀÚ¸¦ ÀûÀýÈ÷ üũÇÏÁö ¾Ê¾Æ¼ HTTP Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö WebLogic ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.vsecurity.com/resources/advisory/20100713-1/ http://www.oracle.com/technetwork/topics/security/cpujul2010-155308.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle WebLogic Server 11gR1 releases Oracle WebLogic Server 10gR3 release Oracle WebLogic Server 10.0 through MP2 Oracle WebLogic Server 9.0, 9.1, 9.2 through MP3 Oracle WebLogic Server 8.1 through SP6 Oracle WebLogic Server 7.0 through SP7 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Oracle »ç´Â ÀÌ ¹®Á¦µéÀ» ÇØ°áÇÒ ¼ö ÀÖ´Â Critical Patch Update¸¦ ³» ³õ¾Ò´Ù. ÀûÀýÇÑ ÆÐÄ¡ ȹµæ ¹× Àû¿ë¿¡ °üÇÑ Á¤º¸´Â ´ÙÀ½ 2010³â 7¿ù Oracle Critical Patch Update¿¡¼ ãÀ» ¼ö ÀÖ´Ù: http://www.oracle.com/technetwork/topics/security/cpujul2010-155308.html |
°ü·Ã URL |
CVE-2010-2375 (CVE) |
°ü·Ã URL |
41620 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|