用友NC IServiceEntryPoint XXE漏洞


漏洞简介

⽤友NC IServiceEntryPoint 接⼝处存在XXE漏洞,未授权的攻击者可以通过此漏洞读取服务器上敏感⽂件,进 ⼀步利⽤可导致服务器失陷。

影响版本

NC65

fofa语法

app="⽤友-UFIDA-NC"

漏洞分析

看下 IServiceEntryPoint 的业务逻辑

package nc.uap.oba.word.webservice;

import nc.bs.framework.common.UserExit;
import nc.uap.oba.Serializer;
import nc.uap.oba.word.webservice.entity.BusinessResult;
import nc.uap.oba.word.webservice.entity.RequestInfo;
import nc.uap.oba.word.webservice.entity.ResponseService;
import nc.uap.oba.word.webservice.handler.CustomServiceHandler;
import nc.uap.oba.word.webservice.handler.ReqServiceHandler;

public class ServiceEntryPointImpl implements IServiceEntryPoint {
    public ServiceEntryPointImpl() {
    }

    public String getResult(String data) {
        BusinessResult result = new BusinessResult();
        result.setSuccessful(false);
        String message = null;

        try {
            RequestInfo reqInfo = (RequestInfo)Serializer.deserialize(data, RequestInfo.class);
            UserExit.getInstance().setUserDataSource(reqInfo.getDsName());
            message = reqInfo.getName();

getResult 方法直接将 data 带入 Serializer.deserialize 方法中,看下其实现逻辑

package nc.uap.oba;

import java.io.StringReader;
import java.io.StringWriter;
import javax.xml.bind.JAXBContext;
import javax.xml.bind.Marshaller;
import javax.xml.bind.Unmarshaller;
import javax.xml.transform.stream.StreamSource;

public class Serializer {
    public Serializer() {
    }

    public static String serialize(Object value) throws Exception {
        StringWriter writer = new StringWriter();
        JAXBContext jaxbContext = JAXBContext.newInstance(new Class[]{value.getClass()});
        Marshaller marshaller = jaxbContext.createMarshaller();
        marshaller.marshal(value, writer);
        return writer.getBuffer().toString();
    }

    public static <T> T deserialize(String xml, Class<?> type) throws Exception {
        JAXBContext jaxbContext = JAXBContext.newInstance(new Class[]{type});
        StreamSource streamSouce = new StreamSource(new StringReader(xml));
        Unmarshaller unmarshaller = jaxbContext.createUnmarshaller();
        return (T)unmarshaller.unmarshal(streamSouce);
    }
}

deserialize 方法里直接使用 javax.xml.bind.Unmarshaller 对 xml 内容进行操作,而JAXB的Unmarshaller默认启用外部实体解析功能,未对XML输入中的实体引用进行限制,造成XXE漏洞。

漏洞复现

漏洞测试

POST /uapws/service/nc.uap.oba.word.webservice.IServiceEntryPoint HTTP/1.1
Host: nc.mrxn.net
Content-Type: text/xml;charset=UTF-8

<?xml version="1.0" encoding="utf-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:iser="http://webservice.word.oba.uap.nc/IServiceEntryPoint">  
  <soapenv:Header/>  
  <soapenv:Body> 
    <iser:getResult> 
      <!--type: string-->  
      <iser:string>XXE POC</iser:string> 
    </iser:getResult> 
  </soapenv:Body> 
</soapenv:Envelope>

DNSLOG 平台成功收到HTTP请求


手机扫码阅读

NetMizer日志管理系统 position.php 命令执行漏洞

用友NC listUserSharingEvents SQL注入漏洞

评 论