CVE-2017-14751, CVE-2017-14753
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 9¿ù 26ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 26ÀÏ¿¡¼ 27ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2017-1531
IBM Business Process Manager 7.5, 8.0, 8.5 ¹öÀüÀÇ XSS Ãë¾àÁ¡À¸·Î »ç¿ëÀÚµéÀÌ ÀÓÀÇÀÇ ÀÚ¹Ù½ºÅ©¸³Æ® Äڵ带 Web UI¿¡ ÀÓº£µå½Ãų ¼ö ÀÖ°Ô ÇØÁØ´Ù. IBM X-Force ID: 130410.
2. CVE-2017-1539
IBM Business Process Manager 7.5, 8.0, 8.5 ¹öÀüÀÇ ±ÇÇÑ »ó½Â Ãë¾àÁ¡À¸·Î LDAP ±×·ì ¸â¹ö½ÊÀ» Á¶ÀÛÇÔÀ¸·Î½á ³ôÀº ±ÇÇÑÀ» ÃëµæÇÒ ¼ö ÀÖ°Ô µÈ´Ù. IBM X-Force ID: 130807.
3. CVE-2017-14749
JerryScript 1.0 ¹öÀüÀÇ jmem_heap_alloc_block_internal Èü ¸Þ¸ð¸® Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Á¶ÀÛµÈ .js ÆÄÀÏÀ» ÅëÇØ DoS °ø°ÝÀ» Çϰųª ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
4. CVE-2017-14751
Intense WP Ç÷¯±×ÀÎ 1.5 ¹öÀüÀÇ XSS Ãë¾àÁ¡ÀÌ´Ù.
5. CVE-2017-14753
EyesOfNetwork À¥ ÀÎÅÍÆäÀ̽º 5.1-0 ¹öÀüÀÇ XSS Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚµéÀÌ ÀÓÀÇÀÇ À¥½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>