English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22495
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Oracle WebLogic ¼­¹ö´Â HTTP Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. new line °ú °°Àº ¿äû Çì´õÀÇ Æ¯¼ö¹®ÀÚ¸¦ ÀûÀýÈ÷ üũÇÏÁö ¾Ê¾Æ¼­ HTTP Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö WebLogic ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.vsecurity.com/resources/advisory/20100713-1/
http://www.oracle.com/technetwork/topics/security/cpujul2010-155308.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle WebLogic Server 11gR1 releases
Oracle WebLogic Server 10gR3 release
Oracle WebLogic Server 10.0 through MP2
Oracle WebLogic Server 9.0, 9.1, 9.2 through MP3
Oracle WebLogic Server 8.1 through SP6
Oracle WebLogic Server 7.0 through SP7
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Oracle »ç´Â ÀÌ ¹®Á¦µéÀ» ÇØ°áÇÒ ¼ö ÀÖ´Â Critical Patch Update¸¦ ³» ³õ¾Ò´Ù. ÀûÀýÇÑ ÆÐÄ¡ ȹµæ ¹× Àû¿ë¿¡ °üÇÑ Á¤º¸´Â ´ÙÀ½ 2010³â 7¿ù Oracle Critical Patch Update¿¡¼­ ãÀ» ¼ö ÀÖ´Ù:
http://www.oracle.com/technetwork/topics/security/cpujul2010-155308.html
°ü·Ã URL CVE-2010-2375 (CVE)
°ü·Ã URL 41620 (SecurityFocus)
°ü·Ã URL (ISS)