CVE-2020-6287 | SAP NetWeaver°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-07-14

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-6287

ʱ    ¼ä

2020-07-14

Àà  ÐÍ

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

SAP NetWeaver 7.3-7.5


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2020Äê7ÔÂ13ÈÕ£¬SAP°ä²¼ÁËÒ»¸ö°²È«¸üУ¬½¨¸´ÁËÒ»¸öSAP NetWeaverÖеÄÑϳÁ·ì϶£¨CVE-2020-6287£©£¬CVSSÆÀ·ÖΪ10·Ö¡£¸Ã·ì϶ԴÓÚSAP NetWeaver AS JavaµÄWeb×é¼þÖжÌȱÉí·ÝÑéÖ¤¡£

×êÑÐÈËÔ±°µÊ¾£¬´Ë°²È«·ì϶Ŀǰ¿ÉÄÜ»áÓ°Ïì40000¶à¸öSAPϵͳ¡£SPA¹«Ë¾»¹·¢ÏÖÖÁÉÙÓÐ2500¸öÒ×Êܹ¥»÷µÄSAPϵͳֱ½Ó¶³öÓÚ»¥ÁªÍø£¬ÆäÖб±ÃÀÕ¼33%£¬Å·ÖÞÕ¼29%ºÍÑÇ̫ռ27%¡£

ÊÜÓ°ÏìµÄSAP²úÆ·ÁбíÈçÏ£º

SAP Enterprise Resource Planning,

SAP Product Lifecycle Management,

SAP Customer Relationship Management,

SAP Supply Chain Management,

SAP Supplier Relationship Management,

SAP NetWeaver Business Warehouse,

SAP Business Intelligence,

SAP NetWeaver Mobile Infrastructure,

SAP Enterprise Portal,

SAP Process Orchestration/Process Integration),

SAP Solution Manager,

SAP NetWeaver Development Infrastructure,

SAP Central Process Scheduling,

SAP NetWeaver Composition Environment, and

SAP Landscape Manager

¸Ã·ì϶¿Éµ¼Ö¶ÁÈ¡¡¢Åú¸ÄºÍɾ³ýSAPϵͳµÄÎļþ£¬²¢Í¨¹ý´´½¨ÌØÈ¨ÕË»§Ö´ÐÐËÁÒâϵͳºÅÁî¡£´Ë±í£¬»¹Äܹ»¸ü¸ÄSAPϵͳÄÚÓû§µÄ¾ßÌåÐÅÏ¢£¨ÕʺÅ£¬IBANµÈ£©ºÍ¶ÁÈ¡Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒÑÔÚ¡°SAP One Support Launchpad¡±°æ±¾½¨¸´¸Ã·ì϶£¬²Î¿¼Á´½Ó£º

https://accounts.sap.com/saml2/idp/sso


0x03 ÓйØÐÂÎÅ


https://www.bleepingcomputer.com/news/security/critical-sap-recon-flaw-exposes-thousands-of-systems-to-attacks/


0x04 ²Î¿¼Á´½Ó


https://us-cert.cisa.gov/ncas/alerts/aa20-195a


0x05 ¹¦·òÏß


2020-07-13 SAP°ä²¼°²È«²¼¸æ

2020-07-14 VSRC°ä²¼·ì϶¹«¸æ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾