Back to overview

CVE-2010-5326

CRITICAL KEV CISA Exploitation: ACTIVE
10.0
CVSS 3.1
Description
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

Metadata

CVE ID
CVE-2010-5326
State
PUBLISHED
Assigner
mitre
Reserved
2016-05-12 00:00 UTC
Published
2016-05-13 10:00 UTC
Last updated
2025-10-21 23:55 UTC
Primary CWE
CWE-306
CWE-306 Missing Authentication for Critical Function
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
SAP NetWeaver Remote Code Execution Vulnerability
Vendor
SAP
Product
NetWeaver
Added to KEV
2021-11-03
Due date
2022-05-03
Ransomware
Not known
Required action
Apply updates per vendor instructions.
CISA description
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-306 adp CWE-306 Missing Authentication for Critical Function
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview