CVE-2020-6287 | SAP NetWeaverÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-07-140x00 Îó²î¸ÅÊö
CVE ID |
CVE-2020-6287 |
ʱ ¼ä |
2020-07-14 |
Àà ÐÍ |
|
µÈ ¼¶ |
ÑÏÖØ |
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
SAP NetWeaver 7.3-7.5 |
0x01 Îó²îÏêÇé
2020Äê7ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬SAPÐû²¼ÁËÒ»¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öSAP NetWeaverÖеÄÑÏÖØÎó²î£¨CVE-2020-6287£©£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ10·Ö¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚSAP NetWeaver AS JavaµÄWeb×é¼þÖÐȱÉÙÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬´ËÇå¾²Îó²îÏÖÔÚ¿ÉÄÜ»áÓ°Ïì40000¶à¸öSAPϵͳ¡£¡£¡£¡£¡£¡£¡£SPA¹«Ë¾»¹·¢Ã÷ÖÁÉÙÓÐ2500¸öÒ×Êܹ¥»÷µÄSAPϵͳֱ½Ó̻¶ÓÚ»¥ÁªÍø£¬£¬£¬£¬£¬£¬£¬ÆäÖб±ÃÀÕ¼33%£¬£¬£¬£¬£¬£¬£¬Å·ÖÞÕ¼29%ºÍÑÇ̫ռ27%¡£¡£¡£¡£¡£¡£¡£
ÊÜÓ°ÏìµÄSAP²úÆ·ÁбíÈçÏ£º
SAP Enterprise Resource Planning,
SAP Product Lifecycle Management,
SAP Customer Relationship Management,
SAP Supply Chain Management,
SAP Supplier Relationship Management,
SAP NetWeaver Business Warehouse,
SAP Business Intelligence,
SAP NetWeaver Mobile Infrastructure,
SAP Enterprise Portal,
SAP Process Orchestration/Process Integration),
SAP Solution Manager,
SAP NetWeaver Development Infrastructure,
SAP Central Process Scheduling,
SAP NetWeaver Composition Environment, and
SAP Landscape Manager
¸ÃÎó²î¿Éµ¼Ö¶ÁÈ¡¡¢Ð޸ĺÍɾ³ýSAPϵͳµÄÎļþ£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý½¨ÉèÌØÈ¨ÕË»§Ö´ÐÐí§ÒâϵͳÏÂÁî¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔ¸ü¸ÄSAPϵͳÄÚÓû§µÄÏêϸÐÅÏ¢£¨Õʺţ¬£¬£¬£¬£¬£¬£¬IBANµÈ£©ºÍ¶ÁȡСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ³§ÉÌÒÑÔÚ¡°SAP One Support Launchpad¡±°æ±¾ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬²Î¿¼Á´½Ó£º
https://accounts.sap.com/saml2/idp/sso
0x03 Ïà¹ØÐÂÎÅ
https://www.bleepingcomputer.com/news/security/critical-sap-recon-flaw-exposes-thousands-of-systems-to-attacks/
0x04 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ncas/alerts/aa20-195a
0x05 ʱ¼äÏß
2020-07-13 SAPÐû²¼Ç徲ͨ¸æ
2020-07-14 VSRCÐû²¼Îó²îͨ¸æ