CVE-2016-5991, CVE-2016-5992
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 11¿ù 24ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 24ÀÏ¿¡¼ 25ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2016-5967
IBM Rational Asset Analyzer(RAA) FP10 ÀÌÀü 6.1.0 ¹öÀüÀÇ ¼³Ä¡ ¿ä¼Ò¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ »ç¿ëÀÚ°¡ IM ·Î±×¸¦ ÀÐ¾î¼ WAS Admin ¾ÏÈ£¸¦ ÃëµæÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù.
2. CVE-2016-5968
IBM Tealeaf Customer Experience 8.7.1.8847 FP10 ÀÌÀü 8.x ¹öÀü, 8.8.0.9049 FP9 ÀÌÀüÀÇ 8.8.x ¹öÀü, 9.0.1.1117 FP5 ÀÌÀüÀÇ 9.0.0 ¹× 9.0.1 ¹öÀü, 9.0.1.5108 FP5 ÀÌÀüÀÇ 9.0.1A ¹öÀü, 9.0.2.1223 FP3 ÀÌÀüÀÇ 9.0.2 ¹öÀü, 9.0.2.5224 FP3 ÀÌÀüÀÇ 9.0.2A ¹öÀüÀÇ Replay ServerÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ SSRF °ø°ÝÀ» ÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
3. CVE-2016-5981
IBM FileNet Workplace XT 1.1.5.2-WPXT-LA011 ¹öÀü, FileNet Workplace(Application Engine) 4.0.2.14-P8AE-IF001 ¹öÀüÀÇ XSS Ãë¾àÁ¡À¸·Î RegExpSecurityFilter¿Í ScriptSecurityFilterÀÌ À߸ø ¼³Á¤µÇ¾úÀ» ¶§ ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®¸¦ ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
4. CVE-2016-5991
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0.6 iFix008 ÀÌÀüÀÇ 4.6.0 ¹öÀü, 4.7.0.4 ÀÌÀüÀÇ 4.7.0 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ »ç¿ëÀÚ°¡ ³ôÀº ±ÇÇÑÀ» ÃëµæÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2016-5992
IBM Sterling Connect:Direct 4.5.00, 4.5.01, 4.6.0.6 iFix008 ÀÌÀüÀÇ 4.6.0 ¹öÀü, 4.7.0.4 ÀÌÀüÀÇ 4.7.0 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ »ç¿ëÀÚ°¡ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>