{"id":5250,"date":"2011-08-13T06:39:50","date_gmt":"2011-08-13T09:39:50","guid":{"rendered":"http:\/\/brainlabs.com.ar\/novedad\/?p=5250"},"modified":"2022-11-28T11:52:35","modified_gmt":"2022-11-28T14:52:35","slug":"gran-falla-de-seguridad-en-sap-netweaver-bh","status":"publish","type":"post","link":"https:\/\/www.brainlabs.com\/novedad\/gran-falla-de-seguridad-en-sap-netweaver-bh\/","title":{"rendered":"Gran falla de seguridad en SAP Netweaver (#bh)"},"content":{"rendered":"<p>El experto en seguridad Alexander Polyakov de ERPScan present\u00f3 un agujero de seguridad del motor J2EE de SAP NetWeaver el cual le permite al atacante crear remotamente nuevas cuentas de administrador. Polyakov demostr\u00f3 la falla en la conferencia de seguridad <a href=\"https:\/\/www.blackhat.com\/\" target=\"_blank\" rel=\"noopener\">Black Hat<\/a> en Las Vegas. Primer busc\u00f3 con Google una cadena particular que es un indicador t\u00edpico del Portal de Management de sistemas SAP.<\/p>\n<p>Luego usando la URL de la b\u00fasqueda us\u00f3 un script Perl que ejecut\u00f3 el ataque en dos pasos. Primero el script crea un usuario nuevo y luego promueve ese nuevo usuario como administrador. Usando ese nuevo usuario luego es posible ingresar al sistema vulnerable.<\/p>\n<p>El script ser\u00e1 publicado por el investigador tres meses despu\u00e9s que SAP publique la actualizaci\u00f3n, dando suficiente tiempo a los clientes de SAP para actualizar sus sistemas.<\/p>\n<p>El investigador no dar\u00e1 m\u00e1s detalles hasta que SAP no haya eliminado la falla con una actualizaci\u00f3n del software.\u201d<\/p>\n<p><strong>Traducci\u00f3n: <\/strong><a href=\"http:\/\/www.segu-info.com.ar\/\" target=\"_blank\" rel=\"noopener\"><strong>Segu-Info<\/strong><\/a><\/p>\n<p><strong>Fuentes:<\/strong><\/p>\n<ul>\n<li>Major security hole in SAP&#8217;s NetWeaver<br \/>\n<a href=\"http:\/\/www.h-online.com\/security\/news\/item\/Major-security-hole-in-SAP-s-NetWeaver-1319808.html\" target=\"_blank\" rel=\"noopener\">http:\/\/www.h-online.com\/security\/news\/item\/Major-security-hole-in-SAP-s-NetWeaver-1319808.html<\/a><\/li>\n<li>SAP Will Issue Patch for NetWeaver Vulnerability<br \/>\nhttp:\/\/www.pcworld.com\/businesscenter\/article\/237373\/sap_will_issue_patch_for_netweaver_vulnerability.html<\/li>\n<li>Next week a half of SAP systems, available in Internet, can be hacked<br \/>\nhttp:\/\/erpscan.com\/press-center\/news\/next-week-a-half-of-sap-systems-available-in-internet-can-be-hacked\/<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>El experto en seguridad Alexander Polyakov de ERPScan present\u00f3 un agujero de seguridad del motor&#8230;<\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-5250","post","type-post","status-publish","format-standard","hentry","category-software"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","covernews-featured":"","covernews-medium":""},"author_info":{"display_name":"Sergio Zamenfeld","author_link":"https:\/\/www.brainlabs.com\/novedad\/author\/sergio\/"},"category_info":"<a href=\"https:\/\/www.brainlabs.com\/novedad\/category\/software\/\" rel=\"category tag\">Software<\/a>","tag_info":"Software","comment_count":"0","_links":{"self":[{"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/posts\/5250","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/comments?post=5250"}],"version-history":[{"count":3,"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/posts\/5250\/revisions"}],"predecessor-version":[{"id":7127,"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/posts\/5250\/revisions\/7127"}],"wp:attachment":[{"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/media?parent=5250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/categories?post=5250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.brainlabs.com\/novedad\/wp-json\/wp\/v2\/tags?post=5250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}