{"id":10218,"date":"2020-08-17T08:00:31","date_gmt":"2020-08-17T06:00:31","guid":{"rendered":"http:\/\/192.168.20.3\/?p=10218"},"modified":"2024-12-11T15:09:14","modified_gmt":"2024-12-11T14:09:14","slug":"sap-security-patch-day-agosto-2020","status":"publish","type":"post","link":"https:\/\/orekait.com\/es\/sap-security-patch-day-agosto-2020\/","title":{"rendered":"SAP Security Patch Day<br><span class=\"font-300\">Agosto 2020<\/span>"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221;][et_pb_row admin_label=&#8221;Imagen principal&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_image src=&#8221;https:\/\/orekait.com\/wp-content\/uploads\/2020\/08\/SAP-Security-Patch-Day.png&#8221; alt=&#8221;cloud-public&#8221; title_text=&#8221;SAP-Security-Patch-Day&#8221; admin_label=&#8221;Imagen principal&#8221; module_class=&#8221;post-img&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row admin_label=&#8221;Cuerpo&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Texto&#8221; _builder_version=&#8221;4.25.2&#8243; header_2_font_size=&#8221;24px&#8221; header_3_font_size=&#8221;20px&#8221; header_4_font_size=&#8221;17px&#8221; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; width=&#8221;%22630%22&#8243; height=&#8221;%22307%22&#8243; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; content__hover_enabled=&#8221;off|hover&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p>Como cada segundo martes de mes, el\u00a0<strong>equipo de seguridad de SAP<\/strong>\u00a0ha compartido las\u00a0<strong>notas de seguridad\u00a0<\/strong>que solucionan vulnerabilidades en los sistemas SAP en el ya denominado\u00a0 \u201cSAP Security Patch Day\u201d. Desde Oreka IT os iremos trayendo estos avisos de forma peri\u00f3dica en el #orekaitblog<\/p>\n<p>Este mes hay\u00a0<strong>15 notas de seguridad<\/strong>\u00a0de las cuales 8 son de prioridad alta con una puntuaci\u00f3n CVSS por encima de 7.<\/p>\n<h2><strong>Qu\u00e9 es CVSS<\/strong><\/h2>\n<div class=\"wp-block-spacer\" aria-hidden=\"true\">\u00a0<\/div>\n<p><strong>CVSS son las siglas de Common Vulnerability Scoring System<\/strong>, un sistema de puntuaci\u00f3n que proporciona un m\u00e9todo est\u00e1ndar y abierto para estimar el impacto de una vulnerabilidad y que se compone de tres grupos principales de m\u00e9tricas: \u00abBase\u00bb, \u00abTemporal\u00bb y de \u00abEntorno\u00bb (Environmental). Cada uno de estos grupos se compone a su vez de un conjunto de m\u00e9tricas. La organizaci\u00f3n responsable de este sistema es la organizaci\u00f3n\u00a0<a href=\"https:\/\/www.first.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">FIRST (Forum of Incident Response and Security Teams)<\/a><\/p>\n<p>Volviendo a SAP, adem\u00e1s de la ya muy comentada vulnerabilidad\u00a0<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-6287\" target=\"_blank\" rel=\"noopener\">CVE-2020-6287<\/a>, tratada en el\u00a0<a href=\"https:\/\/orekait.com\/blog\/vulnerabilidad-critica-en-sap-que-permite-acceso-total-a-los-servidores-sap-nw-java\/\">art\u00edculo<\/a>\u00a0del blog, con la m\u00e1xima puntuaci\u00f3n posible, se suma la siguientes vulnerabilidad con un\u00a0<strong>9 en la puntuaci\u00f3n CVSS<\/strong>:<\/p>\n<p>[<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-6284\" target=\"_blank\" rel=\"noopener\">CVE-2020-6284<\/a>]\u00a0<strong>Cross-Site Scripting (XSS) vulnerability in SAP Netweaver (Knowledge Management)<\/strong><\/p>\n<p>Esta vulnerabilidad que afecta a las versiones de NW 7.30, 7.31, 7.40, 7.50 que utilicen el KM, permite la ejecuci\u00f3n autom\u00e1tica de\u00a0<em>scripts<\/em>\u00a0dentro de un archivo almacenado pudiendo escalar y obtener privilegios comprometiendo la confidencialidad, integridad y disponibilidad del sistema<\/p>\n<p>El siguiente cuadro muestra todas las notas liberadas durante el mes con los sistemas a los que aplica:<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10227 \" src=\"https:\/\/orekait.com\/wp-content\/uploads\/2020\/08\/Notas-Agosto-2020-1.png\" alt=\"\" width=\"853\" height=\"394\" \/><br \/><figcaption><span class=\"has-inline-color has-cyan-bluish-gray-color\">Abre la imagen en una nueva pesta\u00f1a para verla al detalle<\/span><\/figcaption><\/figure>\n<p>En lo que llevamos de a\u00f1o el equipo de seguridad de SAP lleva liberadas 132 notas de seguridad de las cuales 22 tienes una puntuaci\u00f3n CVSS por encima de 9 y 28 por encima de 7.<\/p>\n<figure class=\"wp-block-table\">\n<table>\n<tbody>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">LOW<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">MEDIUM<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">HIGH<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">HOT NEWS<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>TOTAL<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Enero<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">1<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">6<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>7<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Febrero<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">11<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">3<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">1<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>15<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Marzo<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">1<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">9<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">4<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">4<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>18<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Abril<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">16<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">5<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">5<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>26<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Mayo<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">11<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">5<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">6<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>22<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Junio<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">12<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">4<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">2<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>18<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Julio<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">1<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">6<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">1<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">2<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>10<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Agosto<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">\u00a0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">8<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">6<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">2<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>16<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>TOTAL<\/strong><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>3<\/strong><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>79<\/strong><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>28<\/strong><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>22<\/strong><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>132<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>El desglose de notas liberadas por desglose de tipos de vulnerabilidades en lo que llevamos de a\u00f1o es<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10231 \" src=\"https:\/\/orekait.com\/wp-content\/uploads\/2020\/08\/Desglose-Notas-1.png\" alt=\"\" width=\"832\" height=\"417\" \/><br \/><figcaption><span class=\"has-inline-color has-cyan-bluish-gray-color\">Abre la imagen en una nueva pesta\u00f1a para verla al detalle<\/span><\/figcaption><\/figure>\n<p>Menci\u00f3n especial a las 27 brechas de tipo Cross-Site Scripting que permite insertar c\u00f3digo malicioso en paginas web de confianza. En SAP podemos ver estas p\u00e1ginas, por ejemplo, en todos los sistemas que utilicen el Fiori Launchpad.<\/p>\n<p>Tras estos datos objetivos, solo queda recomendar realizar mensualmente un chequeo de las notas de seguridad liberadas por SAP e instalar la que apliquen a los sistemas de cada empresa.<\/p>\n<p>Fuente:\u00a0<a href=\"https:\/\/www.incibe-cert.es\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.incibe-cert.es\/<\/a>\u00a0\u00b7\u00a0<a href=\"https:\/\/wiki.scn.sap.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/wiki.scn.sap.com\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Si tienes preguntas al respecto, puedes dejarlas en el \u00e1rea de comentarios o ponerte en contacto con nuestro departamento de Administraci\u00f3n de Sistemas SAP. Puedes consultar el resto de art\u00edculos sobre los\u00a0<a href=\"https:\/\/orekait.com\/blog\/category\/sap\/administracion-de-sistemas-sap\/sap-security-patch-day\/\">SAP Security Patch Day en este enlace.<\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row admin_label=&#8221;M\u00e1s informaci\u00f3n&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p class=\"morado\">M\u00e1s informaci\u00f3n:<\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;https:\/\/orekait.com\/es\/area-administracion-sistemas&#8221; button_text=&#8221;M\u00e1s informaci\u00f3n&#8221; module_class=&#8221;entrada-btn&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; custom_button=&#8221;on&#8221; button_text_color=&#8221;#8156EA&#8221; button_bg_color=&#8221;RGBA(255,255,255,0)&#8221; button_border_color=&#8221;#8156EA&#8221; button_border_radius=&#8221;30px&#8221; button_font=&#8221;Plus Jakarta Sans|600|||||||&#8221; button_icon=&#8221;&#x24;||divi||400&#8243; button_icon_color=&#8221;#8156EA&#8221; button_on_hover=&#8221;off&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; button_text_color__hover_enabled=&#8221;on|desktop&#8221; button_text_color__hover=&#8221;#8156EA&#8221; button_bg_color__hover_enabled=&#8221;on|hover&#8221; button_bg_color__hover=&#8221;#8156EA&#8221; button_bg_enable_color__hover=&#8221;on&#8221; button_icon_color__hover_enabled=&#8221;on|hover&#8221; button_icon_color__hover=&#8221;#ffffff&#8221; url_new_window=&#8221;on&#8221; sticky_enabled=&#8221;0&#8243;][\/et_pb_button][et_pb_divider show_divider=&#8221;off&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||40px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_divider][\/et_pb_column][\/et_pb_row][et_pb_row use_custom_gutter=&#8221;on&#8221; admin_label=&#8221;Noticias relacionadas titulo&#8221; module_id=&#8221;fondo-articulos&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#f7f7f7&#8243; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_divider show_divider=&#8221;off&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;RGBA(255,255,255,0)&#8221; custom_margin=&#8221;||40px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_divider][et_pb_heading title=&#8221;Quizas te pueda interesar&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; title_level=&#8221;h2&#8243; title_text_align=&#8221;center&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_divider show_divider=&#8221;off&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||30px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_divider][\/et_pb_column][\/et_pb_row][et_pb_row admin_label=&#8221;Noticias relacionadas&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; custom_margin=&#8221;-150px||||false|false&#8221; custom_margin_tablet=&#8221;0px||||false|false&#8221; custom_margin_phone=&#8221;0px||||false|false&#8221; custom_margin_last_edited=&#8221;on|desktop&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_blog fullwidth=&#8221;off&#8221; posts_number=&#8221;3&#8243; include_categories=&#8221;current&#8221; show_author=&#8221;off&#8221; show_date=&#8221;off&#8221; show_pagination=&#8221;off&#8221; _builder_version=&#8221;4.25.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_blog][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Como cada segundo martes de mes, el\u00a0equipo de seguridad de SAP\u00a0ha compartido las\u00a0notas de seguridad\u00a0que solucionan vulnerabilidades en los sistemas SAP en el ya denominado\u00a0 \u201cSAP Security Patch Day\u201d. Desde Oreka IT os iremos trayendo estos avisos de forma peri\u00f3dica en el #orekaitblog Este mes hay\u00a015 notas de seguridad\u00a0de las cuales 8 son de prioridad [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":10220,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"Lorem ipsum dolor sit amet consectetur adipiscing elit congue montes, imperdiet taciti erat elementum fermentum sem ante ultrices ridiculus, sagittis sociis egestas quisque ac semper quis odio. Aenean hendrerit ac metus dis nascetur aliquet mollis integer, rutrum vel laoreet posuere proin sagittis luctus est, tempus duis nisl ultrices parturient tempor praesent. Dignissim curabitur nascetur pellentesque augue fringilla pulvinar eros, tempus fames vehicula maecenas cubilia id, rutrum euismod integer ut scelerisque mus.\r\n\r\nVivamus auctor odio aenean rhoncus natoque dictum purus, volutpat pellentesque laoreet ridiculus consequat nisi varius euismod, augue platea convallis curae magnis taciti. Imperdiet nibh curabitur quisque orci consequat aenean pellentesque, cubilia duis senectus felis sed posuere tortor, magnis enim diam a odio sociis. Enim tellus nisl nec molestie augue luctus tempor habitant, nunc dictumst phasellus volutpat sem facilisis taciti, habitasse laoreet at turpis vel fermentum vulputate.","_et_gb_content_width":"","footnotes":""},"categories":[48,49,50],"tags":[],"class_list":["post-10218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administracion-de-sistemas","category-sap-security","category-sap-security-patch-day"],"_links":{"self":[{"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/posts\/10218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/comments?post=10218"}],"version-history":[{"count":6,"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/posts\/10218\/revisions"}],"predecessor-version":[{"id":21854,"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/posts\/10218\/revisions\/21854"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/media\/10220"}],"wp:attachment":[{"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/media?parent=10218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/categories?post=10218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/orekait.com\/es\/wp-json\/wp\/v2\/tags?post=10218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}