Ãë¾àÁ¡ID |
22564 |
À§Çèµµ |
30 |
Æ÷Æ® |
8880, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¿ø°ÝÀÇ È£½ºÆ®¿¡´Â ÀáÀçÀûÀ¸·Î ´ÙÀ½°ú °°Àº Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â 6.1 Fix Pack 45 ÀÌÀüÀÇ IBM WebSphere ¾îÇø®ÄÉÀÌ¼Ç ¼¹ö°¡ µ¿ÀÛ ÁßÀÌ´Ù: IBM WebSphere Application Server 6.1 Fix Pack 45 ÀÌÀüÀÇ ¹öÀüÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
- Application Snoop Servle¿¡¼ Á¢±ÙÀ» Á¦´ë·Î Á¦¾îÇÏÁö ¸øÇÏ¿© Áß¿äÇÑ Á¤º¸°¡ À¯ÃâµÉ ¼ö ÀÖ´Ù. (CVE-2012-2170, PM56183) - SSL/TLS¿¡ ´Ù¼öÀÇ ¿¡·¯°¡ Á¸ÀçÇÏ¿© °ø°ÝÀÚ°¡ Á¶ÀÛµÈ ClientHello ¸Þ½ÃÁö¸¦ ÅëÇØ ¼ºñ½º °ÅºÎ °ø°ÝÀ» ½ÃµµÇÒ ¼ö ÀÖ´Ù. (CVE-2012-2190, CVE-2012-2191, PM66218) - °ü¸® Äֿܼ¡ XSS ½ºÅ©¸³Æÿ¡ ´ëÇÑ À̽´°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3293, PM60839) - ISC Äֿܼ¡ °ø°ÝÀÚ°¡ »ç¿ëÀÚÀÇ ¼¼¼ÇÀ» Å»ÃëÇÒ ¼ö ÀÖ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3304, PM54356) - °ø°ÝÀÚ°¡ ¼¹öÀÇ °æ·Î¸¦ °Å½½·¯ ¿Ã¶ó°¡¸é¼ µð·ºÅ丮¸¦ ¿¶÷/½ÇÇàÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ¸ç °ø°ÝÀÚ´Â Á¶ÀÛµÈ ¾îÇø®ÄÉÀÌ¼Ç ÆÄÀÏÀ» ÅëÇØ ÀÓÀÇÀÇ ÆÄÀÏÀ» µ¤¾î¾µ ¼ö ÀÖ´Ù. (CVE-2012-3305, PM62467) - 'multi-domain support'°¡ È°¼ºÈ µÇ¾îÀÖÀ» ¶§ ÀÎÁõ ij½Ã¿¡¼ Æнº¿öµå¸¦ ±ú²ýÀÌ Á¦°ÅÇÏÁö ¸øÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3306, PM66514) - z/OS°¡ ½ÇÇàÁßÀÏ ¶§ 'Federated Repositories', 'IIOP'¿¬°á, 'CBIND'üũ, 'Optimized Local Adapters'¿¡ °ü·ÃµÈ ¿¡·¯·Î ÀÎÇØ °ø°ÝÀÚ°¡ º¸¾È¿¡ °üÇÑ Á¦ÇÑ»çÇ×À» ¿ìȸÇÒ ¼ö ÀÖ´Ù. (CVE-2012-3311, PM61388) - PM44303 ÇȽº¿¡ ÀÎÁõÀ» ¿Ã¹Ù¸£°Ô ó¸®ÇÏÁö ¸øÇÏ¿© ÀÎÁõµÈ »ç¿ëÀÚ°¡ ¾îÇø®ÄÉÀ̼ǿ¡ °ü¸®ÀÚ·Î Á¢±ÙÇÒ ¼ö ÀÖ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2012-3325, PM71296)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www-01.ibm.com/support/docview.wss?uid=swg24033269 http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg27007951#61045 https://www-304.ibm.com/support/docview.wss?uid=swg21611311
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: IBM WebSphere Application Server 6.1 Fix Pack 45 ÀÌÀüÀÇ 6.1 ¹öÀüµé |
ÇØ°áÃ¥ |
'IBM Support & downloads' À¥ »çÀÌÆ®ÀÎ http://www-01.ibm.com/support/docview.wss?uid=swg24033269 ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â IBM WebSphere Application ¼¹öÀÇ °¡Àå ÃֽŠ¹öÀü 6.1 (Fix Pack 45 for 6.1 (6.1.0.45) ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2012-2170,CVE-2012-2190,CVE-2012-2191,CVE-2012-3293,CVE-2012-3304,CVE-2012-3305,CVE-2012-3306,CVE-2012-3311,CVE-2012-3325 (CVE) |
°ü·Ã URL |
53755,54743,55149,55185,55309,55671,55678 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|