English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22563
À§Çèµµ 30
Æ÷Æ® 8880, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¿ø°ÝÀÇ È£½ºÆ®¿¡´Â ÀáÀçÀûÀ¸·Î ´ÙÀ½°ú °°Àº Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â 7.0 Fix Pack 25 ÀÌÀüÀÇ IBM WebSphere ¾îÇø®ÄÉÀÌ¼Ç ¼­¹ö°¡ µ¿ÀÛ ÁßÀÌ´Ù:
IBM WebSphere Application Server 7.0 Fix Pack 25 ÀÌÀüÀÇ ¹öÀüÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- SSL/TLS¿¡ ´Ù¼öÀÇ ¿¡·¯°¡ Á¸ÀçÇÏ¿© °ø°ÝÀÚ°¡ Á¶ÀÛµÈ ClientHello ¸Þ½ÃÁö¸¦ ÅëÇØ ¼­ºñ½º °ÅºÎ °ø°ÝÀ» ½ÃµµÇÒ ¼ö ÀÖ´Ù. (CVE-2012-2190, CVE-2012-2191, PM66218)
- °ü¸® Äֿܼ¡ XSS ½ºÅ©¸³Æÿ¡ ´ëÇÑ À̽´°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3293, PM60839)
- ISC Äֿܼ¡ °ø°ÝÀÚ°¡ »ç¿ëÀÚÀÇ ¼¼¼ÇÀ» Å»ÃëÇÒ ¼ö ÀÖ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3304, PM54356)
- °ø°ÝÀÚ°¡ ¼­¹öÀÇ °æ·Î¸¦ °Å½½·¯ ¿Ã¶ó°¡¸é¼­ µð·ºÅ丮¸¦ ¿­¶÷/½ÇÇàÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ¸ç °ø°ÝÀÚ´Â Á¶ÀÛµÈ ¾îÇø®ÄÉÀÌ¼Ç ÆÄÀÏÀ» ÅëÇØ ÀÓÀÇÀÇ ÆÄÀÏÀ» µ¤¾î¾µ ¼ö ÀÖ´Ù. (CVE-2012-3305, PM62467)
- 'multi-domain support'°¡ È°¼ºÈ­ µÇ¾îÀÖÀ» ¶§ ÀÎÁõ ij½Ã¿¡¼­ Æнº¿öµå¸¦ ±ú²ýÀÌ Á¦°ÅÇÏÁö ¸øÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3306, PM66514)
- z/OS°¡ ½ÇÇàÁßÀÏ ¶§ 'Federated Repositories', 'IIOP'¿¬°á, 'CBIND'üũ, 'Optimized Local Adapters'¿¡ °ü·ÃµÈ ¿¡·¯·Î ÀÎÇØ °ø°ÝÀÚ°¡ º¸¾È¿¡ °üÇÑ Á¦ÇÑ»çÇ×À» ¿ìȸÇÒ ¼ö ÀÖ´Ù. (CVE-2012-3311, PM61388)
- PM44303 ÇȽº¿¡ ÀÎÁõÀ» ¿Ã¹Ù¸£°Ô ó¸®ÇÏÁö ¸øÇÏ¿© ÀÎÁõµÈ »ç¿ëÀÚ°¡ ¾îÇø®ÄÉÀ̼ǿ¡ °ü¸®ÀÚ·Î Á¢±ÙÇÒ ¼ö ÀÖ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3325, PM71296)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www-01.ibm.com/support/docview.wss?uid=swg24033267
http://www-01.ibm.com/support/docview.wss?uid=swg27014463#70025
http://www-01.ibm.com/support/docview.wss?uid=swg21611313

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM WebSphere Application Server 7.0 Fix Pack 25 ÀÌÀüÀÇ 7.0 ¹öÀüµé
ÇØ°áÃ¥ 'IBM Support & downloads' À¥ »çÀÌÆ®ÀÎ http://www-01.ibm.com/support/docview.wss?uid=swg24033267 ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â IBM WebSphere Application ¼­¹öÀÇ °¡Àå ÃֽŠ¹öÀü 7.0 (Fix Pack 25 for 7.0 (7.0.0.25) ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2012-2190,CVE-2012-2191,CVE-2012-3293,CVE-2012-3304,CVE-2012-3305,CVE-2012-3306,CVE-2012-3311,CVE-2012-3325 (CVE)
°ü·Ã URL 54743,55149,55185,55309,55671,55678 (SecurityFocus)
°ü·Ã URL (ISS)