CVE-2015-7469, CVE-2015-7480
1. CVE-2015-7414
IBM InfoSphere Master Data Management - Collaborative Edition 11.0.0.0 IF11 ÀÌÀüÀÇ 9.1, 10.1, 11.0 ¹öÀü, 11.3.0.0 IF7 ÀÌÀüÀÇ 11.3 ¹öÀü, 11.4.0.4 IF1 ÀÌÀüÀÇ 11.4 ¹öÀü¿¡ ÀÖ´Â GDS ÄÄÆ÷³ÍÆ® ³» XSS Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ÀÎÁõÀ» ¾òÀº »ç¿ëÀÚ°¡ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.
2. CVE-2015-7467
IBM Jazz Reporting Service 5.0.2-Rational_CLM-ifix011 ÀÌÀüÀÇ 5.x ¹öÀü, 6.0.0-Rational-CLM-ifix005 ÀÌÀüÀÇ 6.0 ¹öÀü¿¡ ÀÖ´Â XSS Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚµéÀÌ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.
3. CVE-2015-7468
IBM Jazz Reporting Service 5.0.2-Rational-CLM-ifix011 ÀÌÀüÀÇ 5.x ¹öÀü, 6.0.0-Rational-CLM-ifix005 ÀÌÀüÀÇ 6.0 ¹öÀü¿¡ ÀÖ´Â Report Builder¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚ°¡ ÀǵµµÈ Á¦ÇÑ ¼³Á¤À» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØÁÖ¸ç °ü¸®ÀÚÀÇ Å½ºÅ© ±ÇÇÑÀ» ¿ìȸÇÏ°Ô ÇØÁØ´Ù.
4. CVE-2015-7469
IBM Jazz Reporting Service 5.0.2-Rational-CLM-ifix011 ÀÌÀüÀÇ 5.x ¹öÀü, 6.0.0-Rational-CLM-ifix005 ÀÌÀüÀÇ 6.0 ¹öÀü ³» Report BuilderÀÇ Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚ°¡ Àбâ Àü¿ë ±ÝÁö ¿É¼ÇÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2015-7470
IBM Jazz Reporting Service 5.0.2-Rational-CLM-ifix011 ÀÌÀüÀÇ 5.x ¹öÀü, 6.0.0-Rational-CLM-ifix005 ÀÌÀüÀÇ 6.0 ¹öÀüÀÇ Report BuilderÀÇ Ãë¾àÁ¡À¸·Î Áß°£ÀÚ °ø°ÝÀ» ÅëÇØ ¹Î°¨ÇÑ Á¤º¸¿¡ Á¢±ÙÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>