IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty, websphere application server 취약점
WebSphere Application Server 및 WebSphere Liberty 8.5, 9.0용 IBM Web Server Plug-ins와 IBM WebSphere Application Server 및 WebSphere Application Server Liberty는 특수하게 조작된 요청을 통한 Web Server Plug-ins의 원격 코드 실행에 취약합니다.
WebSphere Application Server 및 WebSphere Liberty 8.5, 9.0용 IBM Web Server Plug-ins와 IBM WebSphere Application Server 및 WebSphere Application Server Liberty는 특수하게 조작된 요청을 통한 Web Server Plug-ins의 원격 코드 실행에 취약합니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
영향 제품·버전
제품 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty, websphere application server
영향 버전 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty, websphere application server >= 8.5, 9.0, >= 8.5.0.0 <= 8.5.5.29, >= 9.0.0.0 <= 9.0.5.27
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty, websphere application server의 현재 전체 버전이 공식 영향 범위(IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty, websphere application server >= 8.5, 9.0, >= 8.5.0.0 <= 8.5.5.29, >= 9.0.0.0 <= 9.0.5.27)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
공급사 공식 보안 권고에서 영향 버전, 수정 버전, 패치 번호와 공식 완화조치를 먼저 확인해야 합니다.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 수정 버전은 공급사 공식자료 확인 필요 기준을 충족하는지 확인합니다. 이어서 명령어·코드 인젝션 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.