[º¸¾È´º½º ±èÁö¾ð] ½Ã½ºÄÚ »ç´Â Apache Struts2 ÄÄÆ÷³ÍÆ®¸¦ Æ÷ÇÔÇÏ´Â Á¦Ç°±º¿¡¼ Ãë¾àÁ¡ÀÌ ¹ß°ßµÆ´Ù¸ç º¸¾È¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù.
Apache Struts´Â ±â¾÷±Þ ÀÚ¹Ù À¥ ÇÁ·Î±×·¥ ±¸Ãà ÇÁ·¹ÀÓ¿öÅ©´Ù.
À̹ø¿¡ ¹ß°ßµÈ Ãë¾àÁ¡Àº ¿ø°ÝÄÚµå ½ÇÇà Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ OGNL(Object Graph Navigation Language) Ç¥Çö½ÄÀ» Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ Àü¼ÛÇÒ °æ¿ì ¹®Á¦¸¦ À¯¹ß½Ãų ¼ö ÀÖ´Ù.
¿µÇâÀ» ¹Þ´Â Á¦Ç°À¸·Î´Â ¡âCisco Business ¿¡µð¼Ç 3000 ½Ã¸®Áî ¡âCisco Identity Services Engine(ISE) ¡âCisco Media Experience Engine(MXE) 3500 ½Ã¸®Áî ¡âCisco Unified Contact Center(CCE) ¿£ÅÍÇÁ¶óÀÌÁî µîÀÌ ÀÖ´Ù.
ÀÌ¿¡ Ãë¾àÇÑ ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÈ Cisco Àåºñ ¿î¿µÀÚ´Â Âü°í »çÀÌÆ®(http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140709-struts2)¿¡ ¸í½ÃµÅ ÀÖ´Â Affected Products ¹× Software Versions and Fixes ³»¿ëÀ» È®ÀÎÇØ ÆÐÄ¡¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù.
[±èÁö¾ð ±âÀÚ(boan4@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>