漏洞描述
SAP Internet Graphics Servers (IGS) running versions 7.20, 7.20EXT, 7.45, 7.49, or 7.53 has two XML external entity injection (XXE) vulnerabilities within the XMLCHART page - CVE-2018-2392 and CVE-2018-2393. These vulnerabilities occur due to a lack of appropriate validation on the Extension HTML tag when submitting a POST request to the XMLCHART page to generate a new chart.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
launchpad.support.sap.comhttps://launchpad.support.sap.com/#/notes/2525222↗blogs.sap.comhttps://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/↗www.rapid7.comhttps://www.rapid7.com/db/modules/auxiliary/admin/sap/sap_igs_xmlchart_xxe/↗troopers.dehttps://troopers.de/troopers18/agenda/3r38lr/↗github.comhttps://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/sap/sap_igs_xmlchart_xxe.rb↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2018-2392↗