{"id":3489,"date":"2022-04-25T14:27:10","date_gmt":"2022-04-25T05:27:10","guid":{"rendered":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/?p=3489"},"modified":"2023-12-07T14:46:18","modified_gmt":"2023-12-07T05:46:18","slug":"%e3%82%af%e3%83%aa%e3%83%83%e3%82%af%e3%82%b8%e3%83%a3%e3%83%83%e3%82%ad%e3%83%b3%e3%82%b0%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%82%92%e5%9b%9e%e9%81%bf%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95","status":"publish","type":"post","link":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/?p=3489","title":{"rendered":"\u30af\u30ea\u30c3\u30af\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u306e\u8106\u5f31\u6027\u3092\u56de\u907f\u3059\u308b\u65b9\u6cd5"},"content":{"rendered":"<h3>\u6982\u8981<\/h3>\n<p>Applications Manager\u3067\u30af\u30ea\u30c3\u30af\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u306e\u8106\u5f31\u6027\u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306b\u3001frame-ancestors\u30c7\u30a3\u30ec\u30af\u30c6\u30a3\u30d6\u3092\u4f7f\u7528\u3057\u3066Content-Security-Policy\u30d8\u30c3\u30c0\u30fc\u3092\u69cb\u6210\u3057\u307e\u3059\u3002<br \/>\nApplications Manager\u304b\u3089\u8a2d\u5b9a\u3059\u308b\u65b9\u6cd5\u3092\u3054\u7d39\u4ecb\u3044\u305f\u3057\u307e\u3059\u3002<\/p>\n<h3>Applications Manager\u30d3\u30eb\u30c915382\u4ee5\u964d\uff1a<\/h3>\n<p>UI\u304b\u3089\u8a2d\u5b9a\u304c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<ol>\n<li>\uff3b\u7ba1\u7406\uff3d\u307e\u305f\u306f\uff3b\u8a2d\u5b9a\uff3d\u30bf\u30d6\u2192\uff3b\u88fd\u54c1\u8a2d\u5b9a\uff3d\u2192\uff3b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8a2d\u5b9a\uff3d\u306b\u9077\u79fb<\/li>\n<li>\uff3b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5fdc\u7b54\u30d8\u30c3\u30c0\u30fc\uff3d\u6a2a\u306e\uff3b\u8a2d\u5b9a\uff3d\u3092\u30af\u30ea\u30c3\u30af<\/li>\n<li>\u30b3\u30f3\u30c6\u30f3\u30c4\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30dd\u30ea\u30b7\u30fc\u6a2a\u306e\u925b\u7b46\u30a2\u30a4\u30b3\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u3001\u30c1\u30a7\u30c3\u30af\u30de\u30fc\u30af\u306b\u30c1\u30a7\u30c3\u30af\u3092\u5165\u308c\u3001\uff3b\u4fdd\u5b58\uff3d\u3092\u30af\u30ea\u30c3\u30af<br \/>\n\u203bAPM\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u3054\u5229\u7528\u306e\u5834\u5408\u306f\u3001\u30b3\u30f3\u30c6\u30f3\u30c4\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30dd\u30ea\u30b7\u30fc\u6a2a\u306e\uff3b\uff0b\uff3d\u3092\u30af\u30ea\u30c3\u30af\u3057\u3066\u3001OpManager\u306eURL\u3092\u6307\u5b9a\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<blockquote><p>\u4f8b\uff1ahttp:\/\/&lt;opm-host&gt;:&lt;opm-port&gt;<\/p><\/blockquote>\n<p><a href=\"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/wp-content\/uploads\/sites\/11\/3489-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-4438\" src=\"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/wp-content\/uploads\/sites\/11\/3489-1-1024x416.png\" alt=\"\" width=\"1024\" height=\"416\" srcset=\"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/wp-content\/uploads\/sites\/11\/3489-1-1024x416.png 1024w, https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/wp-content\/uploads\/sites\/11\/3489-1-300x122.png 300w, https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/wp-content\/uploads\/sites\/11\/3489-1.png 1384w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/li>\n<\/ol>\n<h3>Applications Manager\u30d3\u30eb\u30c914845\u3001\u30d3\u30eb\u30c915004\uff1a<\/h3>\n<ol>\n<li>Applications Manager\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u30d5\u30a9\u30eb\u30c0\u30fc\\ working \\ WEB-INF \\ backup\u306b\u79fb\u52d5\u3057\u3001web.xml\u30d5\u30a1\u30a4\u30eb\u306e\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3092\u53d6\u308a\u307e\u3059\u3002<\/li>\n<li>web.xml\u30d5\u30a1\u30a4\u30eb\u5185\u3067\u3001\u6b21\u306e\u884c\u3092\u691c\u7d22\u3057\u3066\u304f\u3060\u3055\u3044\u3002<br \/>\n&lt;!-- Uncomment the following code to enable protection against click jacking. --&gt;<\/li>\n<li>\u5148\u982d\u306e\u300c&lt;\uff01-\u300d\u3068\u672b\u5c3e\u306e\u300c-&gt;\u300d\u3092\u524a\u9664\u3057\u3066\u3001\u30af\u30ea\u30c3\u30af\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u306e\u9632\u6b62\u306b\u4f7f\u7528\u3055\u308c\u308b\u30b3\u30fc\u30c9\u306e\u30b3\u30e1\u30f3\u30c8\u3092\u89e3\u9664\u3057\u307e\u3059\u3002<\/li>\n<\/ol>\n<blockquote>\n<p style=\"padding-left: 40px\">\u30c7\u30d5\u30a9\u30eb\u30c8\uff1a<br \/>\n&lt;!-- Uncomment the following code to enable protection against click jacking. --&gt;<br \/>\n<span style=\"color: #ff0000\">&lt;!--<\/span><br \/>\n&lt;init-param&gt;<br \/>\n&lt;param-name&gt;xFrameOptions&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;SAMEORIGIN&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<br \/>\n&lt;init-param&gt;<br \/>\n&lt;param-name&gt;contentSecurityPolicy&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;frame-ancestors 'self'&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<br \/>\n<span style=\"color: #ff0000\">--&gt;<\/span><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"padding-left: 40px\">\u5909\u66f4\u4f8b\uff1a<br \/>\n&lt;!-- Uncomment the following code to enable protection against click jacking. --&gt;<br \/>\n&lt;init-param&gt;<br \/>\n&lt;param-name&gt;xFrameOptions&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;SAMEORIGIN&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<br \/>\n&lt;init-param&gt;<br \/>\n&lt;param-name&gt;contentSecurityPolicy&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;frame-ancestors 'self'&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<\/p>\n<\/blockquote>\n<p>\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u3066\u3001Applications Manager\u3092\u518d\u8d77\u52d5\u3057\u3001\u554f\u984c\u304c\u89e3\u6c7a\u3057\u305f\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h3>APM\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u5834\u5408\uff1a<\/h3>\n<p>APM\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u5834\u5408\u3001\u4e0a\u8a18Applications Manager\u306e\u30b3\u30fc\u30c9\u8a2d\u5b9a\u4f8b\u306e\"&lt;param-value&gt;\"\u306b\u306f\u3001<br \/>\nSAMEORIGIN\u3067\u306f\u306a\u304fOPM\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u6307\u5b9a\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<blockquote><p>&lt;init-param&gt;<br \/>\n&lt;param-name&gt;xFrameOptions&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;ALLOW-FROM<span style=\"color: #ff0000\"> &lt;source&gt;<\/span>&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<br \/>\n&lt;init-param&gt;<br \/>\n&lt;param-name&gt;contentSecurityPolicy&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;frame-ancestors<span style=\"color: #ff0000\"> &lt;source&gt;<\/span>;&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<\/p><\/blockquote>\n<p>&lt;source&gt;\u3092\u3001\u30d5\u30ec\u30fc\u30e0\u5185\u3067\u30b5\u30a4\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u30c9\u30e1\u30a4\u30f3\u306b\u7f6e\u304d\u63db\u3048\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<blockquote><p>\u4f8b \uff1a<br \/>\n&lt;init-param&gt;<br \/>\n&lt;param-name&gt;xFrameOptions&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;ALLOW-FROM <span style=\"color: #ff0000\">https:\/\/example.com\/<\/span>&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<br \/>\n&lt;init-param&gt;<br \/>\n&lt;param-name&gt;contentSecurityPolicy&lt;\/param-name&gt;<br \/>\n&lt;param-value&gt;frame-ancestors <span style=\"color: #ff0000\">https:\/\/example.com\/<span style=\"color: #000000\">;<\/span><\/span>&lt;\/param-value&gt;<br \/>\n&lt;\/init-param&gt;<\/p><\/blockquote>\n<p>\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u3066\u3001Applications Manager\u3092\u518d\u8d77\u52d5\u3057\u3001\u554f\u984c\u304c\u89e3\u6c7a\u3057\u305f\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p><a href=\"https:\/\/pitstop.manageengine.com\/portal\/en\/kb\/articles\/how-to-avoid-the-clickjacking-vulnerability-in-appmanager\" target=\"_blank\" rel=\"noopener\">\u672c\u793e\u7248\u30ca\u30ec\u30c3\u30b8<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 Applications Manager\u3067\u30af\u30ea\u30c3\u30af\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u306e\u8106\u5f31\u6027\u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306b\u3001frame-ancestors\u30c7\u30a3\u30ec\u30af\u30c6\u30a3\u30d6\u3092\u4f7f\u7528\u3057\u3066C\u2026 <a href=\"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/?p=3489\" class=\"more\">\uff3b\u7d9a\u304d\u3092\u8aad\u3080\uff3d<\/a><\/p>\n","protected":false},"author":47,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[223],"tags":[],"class_list":["post-3489","post","type-post","status-publish","format-standard","hentry","category-3-security-apm"],"modified_by":"manami","_links":{"self":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=\/wp\/v2\/posts\/3489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3489"}],"version-history":[{"count":13,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=\/wp\/v2\/posts\/3489\/revisions"}],"predecessor-version":[{"id":4439,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=\/wp\/v2\/posts\/3489\/revisions\/4439"}],"wp:attachment":[{"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.manageengine.jp\/support\/kb\/Applications_Manager\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}