{"id":2576,"date":"2021-02-17T09:24:53","date_gmt":"2021-02-17T14:24:53","guid":{"rendered":"https:\/\/cert.pa\/?p=2576"},"modified":"2021-02-17T09:24:53","modified_gmt":"2021-02-17T14:24:53","slug":"csirt-panama-aviso-2021-02-15-sap-actualizacion-de-seguridad-de-sap-de-febrero-de-2021","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=2576","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2021-02-15 SAP: Actualizaci\u00f3n de seguridad de SAP de febrero de 2021"},"content":{"rendered":"\n<p>CSIRT Panam\u00e1 Aviso 2021-02-15 SAP: Actualizaci\u00f3n de\nseguridad de SAP de febrero de 2021<\/p>\n\n\n\n<p>Gravedad: Alta&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Fecha de publicaci\u00f3n: Febrero 15,\n2021<br>\n\u00daltima revisi\u00f3n: Febrero 15, 2021<\/p>\n\n\n\n<p>Sitio web: https:\/\/support.sap.com\/<br>\nSistemas Afectados: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>SAP Business Client, versi\u00f3n 6.5;<\/li><li>SAP Commerce, versiones 1808, 1811, 1905, 2005 y\n2011;<\/li><li>SAP Business Warehouse, versiones 710, 711, 730,\n731, 740, 750, 751, 752, 753, 754, 755 y 782;<\/li><li>SAP NetWeaver AS ABAP (SAP Landscape Transformation\n&#8211; DMIS), versiones 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730,\n2011_1_731 y 2011_1_752, 2020;<\/li><li>SAP S4 HANA (SAP Landscape Transformation),\nversiones 101, 102, 103, 104 y 105;<\/li><li>SAP NetWeaver AS ABAP, versiones 740, 750, 751,\n752, 753, 754 y 755;<\/li><li>SAP Software Provisioning Manager 1.0 (SAP\nNetWeaver Master Data Management Server 7.1), versi\u00f3n 1.0;<\/li><li>SAP NetWeaver Process Integration (Java Proxy\nRuntime), versiones 7.10, 7.11, 7.30, 7.31, 7.40 y 7.50;<\/li><li>SAP Business Objects Business Intelligence Platform\n(CMC and BI Launchpad), versiones 410, 420 y 430;<\/li><li>SAP UI5, versiones 1.38.49, 1.52.49, 1.60.34,\n1.71.31, 1.78.18, 1.84.5, 1.85.4 y 1.86.1;<\/li><li>SAP Web Dynpro ABAP;<\/li><li>SAP UI, versiones 7.5, 7.51, 7.52, 7.53 y 7.54;<\/li><li>SAP UI 700, versi\u00f3n 2.0;<\/li><li>SAP HANA Database, versiones 1.0 y 2.0;<\/li><li>SAP NetWeaver Master Data Management Server,\nversiones 710 y 710.750.. &nbsp;<\/li><li><strong>Descripci\u00f3n<\/strong><\/li><\/ul>\n\n\n\n<p>Vulnerabilidades cr\u00edticas que afectan a diferentes\nproductos SAP, en su reportes de parches de seguridad del mes de febrero, ha\nemitido un total de 7 notas de seguridad y 6 actualizaciones de notas\nanteriores, siendo 3 de severidad cr\u00edtica, 2 altas y 8 medias.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>Impacto<\/strong><\/li><\/ol>\n\n\n\n<p>Los tipos de vulnerabilidades publicadas se\ncorresponden con los siguientes:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>1\nvulnerabilidad de secuestro del click,<\/li><li>1\nvulnerabilidad de Cross Site Scripting,<\/li><li>1\nvulnerabilidad de denegaci\u00f3n de servicio,<\/li><li>3\nvulnerabilidades de falta de comprobaci\u00f3n de autorizaci\u00f3n,<\/li><li>1\nvulnerabilidad de ejecuci\u00f3n remota de c\u00f3digo,<\/li><li>1\nvulnerabilidad de SQL injection,<\/li><li>6\nvulnerabilidades de otro tipo.<\/li><\/ul>\n\n\n\n<p>Vulnerabilidad: CVE-2021-21477 <\/p>\n\n\n\n<p>Un atacante autenticado, con privilegios para\neditar las reglas drools en SAP Commerce Cloud, podr\u00eda ser capaz de inyectar\nc\u00f3digo malicioso en ellas. Esto permitir\u00eda la ejecuci\u00f3n remota de c\u00f3digo cuando\nlas reglas son ejecutadas, pudiendo comprometer el host subyacente y afectar a\nla confidencialidad, integridad y disponibilidad de la aplicaci\u00f3n. <\/p>\n\n\n\n<p>Vulnerabilidad: Tabnabbing inverso <\/p>\n\n\n\n<p>Este fallo podr\u00eda permitir que un documento\nenlazado, que se abra en una nueva pesta\u00f1a o ventana del navegador, redirija o\nreemplace la p\u00e1gina original por una p\u00e1gina de phishing sin ninguna interacci\u00f3n\npor parte del usuario.<\/p>\n\n\n\n<p><strong>III. Referencia a soluciones, herramientas e\ninformaci\u00f3n<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Actualizaci\u00f3n de SAP en su sitio oficial, en el\nsiguiente enlace: https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news.html<\/p>\n\n\n\n<p><strong>Fuentes:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Common Vulnerabilities and Exposures. Recopilado\nen: https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-21477<\/li><li>CSIRT\nChile. 15 de febrero del 2021. Vulnerabilidades. Recopilado en: <a href=\"https:\/\/www.csirt.gob.cl\/vulnerabilidades\/9vsa21-00390-01\/\">https:\/\/www.csirt.gob.cl\/vulnerabilidades\/9vsa21-00390-01\/<\/a><\/li><li>INCIBE-CERT. Actualizaci\u00f3n de\nseguridad de SAP de febrero de 2021. Recopilado en: https:\/\/www.incibe-cert.es\/alerta-temprana\/avisos-seguridad\/actualizacion-seguridad-sap-febrero-2021<\/li><\/ul>\n\n\n\n<p><strong>Informaci\u00f3n de contacto<\/strong><br>\nCSIRT PANAMA<br>\nComputer Security Incident Response Team Autoridad Nacional para la Innovacion\nGubernamental<br>\nE-Mail: info@cert.pa<br>\nPhone: +507 520-CERT (2378)<br>\nWeb: https:\/\/cert.pa<br>\nTwitter: @CSIRTPanama<br>\nKey ID: 16F2B124<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CSIRT Panam\u00e1 Aviso 2021-02-15 SAP: Actualizaci\u00f3n de seguridad de SAP de febrero de 2021 Gravedad: Alta&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Fecha de publicaci\u00f3n: Febrero 15, 2021 \u00daltima revisi\u00f3n: Febrero 15, 2021 Sitio web: https:\/\/support.sap.com\/ Sistemas Afectados: SAP Business Client,&#8230;<\/p>\n","protected":false},"author":4,"featured_media":2578,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[76,72,135],"class_list":["post-2576","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad","tag-actualizaciones","tag-avisos-de-seguridad","tag-sap"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2576"}],"version-history":[{"count":1,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2576\/revisions"}],"predecessor-version":[{"id":2577,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2576\/revisions\/2577"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/2578"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}