sap-netweaver-portal: SAP NetWeaver Portal - Detect

日期: 2025-09-01 | 影响软件: SAP NetWeaver Portal | POC: 已公开

漏洞描述

SAP NetWeaver Portal login has been detected. Note that NetWeaver has multiple default passwords as listed in the references.

PoC代码[已公开]

id: sap-netweaver-portal

info:
  name: SAP NetWeaver Portal - Detect
  author: organiccrap
  severity: info
  description: SAP NetWeaver Portal login has been detected. Note that NetWeaver has multiple default passwords as listed in the references.
  reference:
    - https://www.sap.com/products/technology-platform/netweaver.html
    - https://www.cisoplatform.com/profiles/blogs/sap-netweaver-abap-security-configuration-part-2-default
  tags: panel,sap
  created: 2024/04/15

rules:
  r0:
    request:
      method: GET
      path: /irj/portal
    expression: response.status == 200 && response.body.bcontains(b'<title>SAP&#x20;NetWeaver&#x20;Portal</title>')
expression: r0()

相关漏洞推荐