SAP Internet Graphics Service HTTP请求远程拒绝服务漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1193838 漏洞类型
发布时间 2006-08-14 更新时间 2006-08-15
CVE编号 CVE-2006-4134 CNNVD-ID CNNVD-200608-217
漏洞平台 N/A CVSS评分 5.0
|漏洞来源
https://cxsecurity.com/issue/WLB-2006080099
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200608-217
|漏洞详情
InternetGraphicsServer(IGS)是SAPR/3企业环境的一个组件,可提供图形服务。IGS的Web应用服务器实现上漏洞,远程攻击者可以通过利用此漏洞对服务器执行拒绝服务攻击,导致应用服务器进程中止。
|漏洞EXP
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

(The following advisory is also available in PDF format for download at:
http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_SAP_IGS_Remote_D
enial_of_Service.pdf )

CYBSEC S.A.
www.cybsec.com

Pre-Advisory Name: SAP Internet Graphics Service (IGS) Remote Denial of Service
==================

Vulnerability Class: Design Flaw
====================

Release Date: 08/10/2006
=============

Affected Applications:
======================
* SAP IGS 6.40 Patchlevel <= 15
* SAP IGS 7.00 Patchlevel <= 3

Affected Platforms:
===================
* AIX 64 bits
* HP-UX on IA64 64bit
* HP-UX on PA-RISC 64bit
* Linux on IA64 64bit
* Linux on Power 64bit
* Linux on x86_64 64bit
* Linux on zSeries 64bit
* OS/400 V5R2M0
* Solaris on SPARC 64bit
* TRU64 64bit

Local / Remote: Remote
===============

Severity: Medium
=========

Author:  Mariano Nu?ez Di Croce
=======

Vendor Status:
==============
* Confirmed, update released.

Reference to Vulnerability Disclosure Policy:
=============================================
http://www.cybsec.com/vulnerability_policy.pdf

Product Overview:
==================
"The IGS provides a server architecture where data from an SAP System or other sources can be used to generate graphical or non-graphical output."

It is important to note that IGS is installed and activated by default with the Web Application Server (versions >= 6.30)

Vulnerability Description:
==========================
A specially crafted HTTP request can derive in the finalization of SAP IGS Service.

Technical Details:
==================
Technical details will be released three months after publication of this pre-advisory. This was agreed upon with SAP to allow their customers to upgrade affected software prior to technical knowledge
been publicly available.

Impact:
=======
Successful exploitation of this vulnerability allows to remotely shutdown SAP IGS service.

Solutions:
==========
SAP has released patches to address this vulnerability. Affected customers should apply the patches immediately.
More information can be found on SAP Note 968423.

Vendor Response:
================
* 06/02/2006: Initial Vendor Contact.
* 06/09/2006: Vendor Confirmed Vulnerability.
* 07/03/2006: Vendor Releases Update for version 6.40.
* 07/13/2006: Vendor Releases Update for version 7.00.
* 08/10/2006: Pre-Advisory Public Disclosure.

Special Thanks:
===============
Thanks goes to Carlos Diaz and Victor Montero.

Contact Information:
====================
For more information regarding the vulnerability feel free to contact the author at mnunez {at} cybsec.com. Please bear in mind that technical details will be disclosed to the general public three
months after the release of this pre-advisory.

For more information regarding CYBSEC: www.cybsec.com
(c) 2006 - CYBSEC S.A. Security Systems
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFE237ibbZGNCayCJkRAtwiAKCcrabY31w6WuNDEKKeduFjqVYXzwCdHzvX
jRGCfJtxedojYXV3gS/y6rg=
=amVH
-----END PGP SIGNATURE-----
|参考资料

来源:XF
名称:sap-igs-http-dos(28328)
链接:http://xforce.iss.net/xforce/xfdb/28328
来源:BID
名称:19469
链接:http://www.securityfocus.com/bid/19469
来源:BUGTRAQ
名称:20060810CYBSEC-SecurityPre-Advisory:SAPInternetGraphicsService(IGS)RemoteDenialofService
链接:http://www.securityfocus.com/archive/1/archive/1/442838/100/0/threaded
来源:VUPEN
名称:ADV-2006-3267
链接:http://www.frsirt.com/english/advisories/2006/3267
来源:MISC
链接:http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_SAP_IGS_Remote_Denial_of_Service.pdf
来源:SECTRACK
名称:1016675
链接:http://securitytracker.com/id?1016675
来源:SECUNIA
名称:21448
链接:http://secunia.com/advisories/21448
来源:FULLDISC
名称:20060810CYBSEC-SecurityPre-Advisory:SAPInternetGraphicsService(IGS)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=115524314804055&w=2
来源:SREASON
名称:1390
链接:http://securityreason.com/securityalert/1390