sap-fiorilaunchpad-logon: Fiori Launchpad Login Panel - Detect

日期: 2025-09-01 | 影响软件: SAP Fiori LaunchPad | POC: 已公开

漏洞描述

Fiori Launchpad login panel was detected.

PoC代码[已公开]

id: sap-fiorilaunchpad-logon

info:
  name: Fiori Launchpad Login Panel - Detect
  author: dhiyaneshDK
  severity: info
  description: Fiori Launchpad login panel was detected.
  reference:
    - https://www.exploit-db.com/ghdb/6793
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
    cwe-id: CWE-200
    cpe: cpe:2.3:a:sap:fiori_launchpad:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    product: fiori_launchpad
    vendor: sap
  tags: panel,edb,sap
  created: 2024/04/15

rules:
  r0:
    request:
      method: GET
      path: /sap/bc/ui5_ui5/ui2/ushell/shells/abap/FioriLaunchpad.html?saml2=disabled
    expression: |
      response.status == 200 && 
      (response.body.bcontains(b'<title>Logon</title>') || response.body.bcontains(b'<title>登录</title>')) && 
      response.body.bcontains(b'SAP SE')
expression: r0()

相关漏洞推荐