SAP NetWeaver AS Java ÑÏÖØÎó²î (CVE-2020-6287) Ç徲ͨ¸æ
2020-07-15
×ÛÊö
ÍâµØÊ±¼ä2020Äê7ÔÂ13ÈÕ£¬SAPÐû²¼Çå¾²¸üÐÂÌåÏÖ£¬ÐÞ¸´ÁËÒ»¸ö±£´æÓÚSAP NetWeaver AS Java£¨LMÉèÖÃÏòµ¼£©7.30ÖÁ7.50°æ±¾ÖеÄÑÏÖØÎó²îCVE-2020-6287¡£
Îó²îÔµÓÚSAP NetWeaver AS for Java Web×é¼þÖÐȱÉÙÉí·ÝÑéÖ¤£¬Òò´ËÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄSAPϵͳÉϾÙÐиßÌØÈ¨Ô˶¯¡£
ÈôÊDZ»ÀÖ³ÉʹÓã¬Ôòδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý½¨Éè¾ßÓÐ×î´óÌØÈ¨µÄÐÂSAPÓû§£¬ÈƹýËùÓлá¼ûºÍÊÚȨ¿ØÖÆ£¬´Ó¶øÍêÈ«¿ØÖÆSAPϵͳ¡£
CVSS 3.0ÆÀ·Ö10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H¡£
²Î¿¼Á´½Ó£º
https://us-cert.cisa.gov/ncas/alerts/aa20-195a
ÊÜÓ°Ïì²úÆ·
SAP NetWeaver AS JAVA (LM ÉèÖÃÏòµ¼) Versions = 7.30, 7.31, 7.40, 7.50
DZÔÚÒ×Êܹ¥»÷µÄSAPÓªÒµ½â¾ö¼Æ»®°üÀ¨£¨µ«²»ÏÞÓÚ£©£º
SAP Enterprise Resource Planning(ERP),
SAP Product Lifecycle Management,
SAP Customer Relationship Management,
SAP Supply Chain Management(SCM),
SAP Supplier Relationship Management,
SAP NetWeaver Business Warehouse,
SAP Business Intelligence,
SAP NetWeaver Mobile Infrastructure,
SAP Enterprise Portal,
SAP Process Orchestration/Process Integration,
SAP Solution Manager,
SAP NetWeaver Development Infrastructure,
SAP Central Process Scheduling,
SAP NetWeaver Composition Environment, and
SAP Landscape Manager.
½â¾ö¼Æ»®
¹Ù·½ÒÑΪÊÜÓ°Ïì×é¼þÐû²¼Á˲¹¶¡¡£Ç¿ÁÒ½¨ÒéÏà¹Ø¿Í»§Á¬Ã¦×°ÖøüС£
https://launchpad.support.sap.com/
ÎÞ·¨Á¬Ã¦ÐÞ²¹µÄ×é֯Ӧͨ¹ý½ûÓÃLMÉèÖÃÏòµ¼·þÎñÀ´»º½â¸ÃÎó²î£¨Çë²ÎÔÄSAPÇ徲˵Ã÷££2939665£©¡£
https://launchpad.support.sap.com/#/notes/2939665
ÈôÊÇÕâЩѡÏî¶¼²»¿ÉÓ㬻òÕß²Ù×÷½«ÆÆ·ÑÁè¼Ý24Сʱ²Å»ªÍê³É£¬Ôò½¨ÒéÇ×½ü¼àÊÓSAP NetWeaver ASµÄÒì³£Ô˶¯¡£
¹Ù·½Çå¾²¸üУº
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







