CVE-2010-5326 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 17.8% (pctl 97)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 17.77% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2016-05-13 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | SAP NetWeaver Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | SAP / NetWeaver |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| sap | netweaver application server java |
References
- http://service.sap.com/sap/support/notes/1445998
- http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutions
- http://www.securityfocus.com/bid/48925
- http://www.securityfocus.com/bid/90533
- http://www.us-cert.gov/ncas/alerts/TA16-132A
- https://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applications
- http://service.sap.com/sap/support/notes/1445998
- http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutions
- http://www.securityfocus.com/bid/48925
- http://www.securityfocus.com/bid/90533
- http://www.us-cert.gov/ncas/alerts/TA16-132A
- https://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applications
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-5326
→ the Explorer · watch your stack · NVD