CVE-2010-5326
sap netweaver application server java
Published 13 May 2016 · updated 16 Jun 2026 · Analyzed
10.0 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
References
- service.sap.com/sap/support/notes/1445998 · Permissions Required
- www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutions · Broken Link
- www.securityfocus.com/bid/48925 · Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/90533 · Third Party Advisory, VDB Entry
- www.us-cert.gov/ncas/alerts/TA16-132A · Third Party Advisory, US Government Resource
- www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applications · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-5326 · US Government Resource