CVE-2020-6287 | SAP NetWeaver°²È«·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-07-140x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-6287 |
ʱ ¼ä |
2020-07-14 |
|
Àà ÐÍ |
|
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
SAP NetWeaver 7.3-7.5 |
0x01 ·ì϶ÏêÇé
2020Äê7ÔÂ13ÈÕ£¬SAP°ä²¼ÁËÒ»¸ö°²È«¸üУ¬½¨¸´ÁËÒ»¸öSAP NetWeaverÖеÄÑϳÁ·ì϶£¨CVE-2020-6287£©£¬CVSSÆÀ·ÖΪ10·Ö¡£¸Ã·ì϶ԴÓÚSAP NetWeaver AS JavaµÄWeb×é¼þÖжÌȱÉí·ÝÑéÖ¤¡£
×êÑÐÈËÔ±°µÊ¾£¬´Ë°²È«·ì϶Ŀǰ¿ÉÄÜ»áÓ°Ïì40000¶à¸öSAPϵͳ¡£SPA¹«Ë¾»¹·¢ÏÖÖÁÉÙÓÐ2500¸öÒ×Êܹ¥»÷µÄSAPϵͳֱ½Ó¶³öÓÚ»¥ÁªÍø£¬ÆäÖб±ÃÀÕ¼33%£¬Å·ÖÞÕ¼29%ºÍÑÇ̫ռ27%¡£
ÊÜÓ°ÏìµÄSAP²úÆ·ÁбíÈçÏ£º
SAP Enterprise Resource Planning,
SAP Product Lifecycle Management,
SAP Customer Relationship Management,
SAP Supply Chain Management,
SAP Supplier Relationship Management,
SAP NetWeaver Business Warehouse,
SAP Business Intelligence,
SAP NetWeaver Mobile Infrastructure,
SAP Enterprise Portal,
SAP Process Orchestration/Process Integration),
SAP Solution Manager,
SAP NetWeaver Development Infrastructure,
SAP Central Process Scheduling,
SAP NetWeaver Composition Environment, and
SAP Landscape Manager
¸Ã·ì϶¿Éµ¼Ö¶ÁÈ¡¡¢Åú¸ÄºÍɾ³ýSAPϵͳµÄÎļþ£¬²¢Í¨¹ý´´½¨ÌØÈ¨ÕË»§Ö´ÐÐËÁÒâϵͳºÅÁî¡£´Ë±í£¬»¹Äܹ»¸ü¸ÄSAPϵͳÄÚÓû§µÄ¾ßÌåÐÅÏ¢£¨Õʺţ¬IBANµÈ£©ºÍ¶ÁÈ¡Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒÑÔÚ¡°SAP One Support Launchpad¡±°æ±¾½¨¸´¸Ã·ì϶£¬²Î¿¼Á´½Ó£º
https://accounts.sap.com/saml2/idp/sso
0x03 ÓйØÐÂÎÅ
https://www.bleepingcomputer.com/news/security/critical-sap-recon-flaw-exposes-thousands-of-systems-to-attacks/
0x04 ²Î¿¼Á´½Ó
https://us-cert.cisa.gov/ncas/alerts/aa20-195a
0x05 ¹¦·òÏß
2020-07-13 SAP°ä²¼°²È«²¼¸æ
2020-07-14 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ