보안 권고문

IBM 제품 보안 업데이트 권고

개요


IBM은 IBM WebSphere Application Server와 WebSphere Application Server – Liberty에서 발생하는 취약점을 해결하는 보안 업데이트를 발표했다. 해당 제품 사용자는 최신 버전 또는 지정된 Interim Fix를 적용해야 한다.

대상 제품 및 취약점


  • CVE-2026-14529: IBM WebSphere Application Server 및 WebSphere Application Server – Liberty에 영향을 주는 서버 측 요청 위조(Server-Side Request Forgery, SSRF) 취약점이다.
  • CVE-2026-15057: IBM WebSphere Application Server – Liberty에 영향을 주는 비제어 힙 할당으로 인한 서비스 거부(denial of service) 취약점이다.

영향받는 버전과 해결 버전


  • CVE-2026-14529
    • IBM WebSphere Application Server 8.5.0.0 이상 8.5.5.30
    • IBM WebSphere Application Server 9.0.0.0 이상 9.0.5.28
    • IBM WebSphere Application Server – Liberty 17.0.0.3 이상 26.0.0.8
    • 해결 버전: IBM WebSphere Application Server 8.5.5.31 이상, 9.0.5.29 이상, IBM WebSphere Application Server – Liberty 26.0.0.9 이상, 또는 APAR DT495928 Interim Fix, APAR PH72053 Interim Fix 적용
  • CVE-2026-15057
    • IBM WebSphere Application Server – Liberty 17.0.0.3 이상 26.0.0.7
    • 해결 버전: IBM WebSphere Application Server – Liberty 26.0.0.8 이상, 또는 APAR PH72167 Interim Fix 적용

조치 사항


IBM은 참고 사이트의 안내에 따라 최신 취약점 패치 버전으로 업데이트할 것을 안내했다.