{
  "id": "CVE-2010-5326",
  "url": "https://spydr.io/cve/CVE-2010-5326",
  "published": "2016-05-13T10:59:00.173Z",
  "modified": "2026-06-16T23:26:33.823Z",
  "score": 10,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.1777,
  "epss_percentile": 0.97096,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "SAP NetWeaver Remote Code Execution Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2010-5326"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "sap"
  ],
  "products": [
    "sap netweaver application server java"
  ],
  "cwes": [
    "CWE-306"
  ],
  "description": "The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a \"Detour\" attack.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 10,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://service.sap.com/sap/support/notes/1445998",
      "tags": [
        "Permissions Required"
      ]
    },
    {
      "url": "http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutions",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/48925",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/90533",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.us-cert.gov/ncas/alerts/TA16-132A",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ]
    },
    {
      "url": "https://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applications",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-5326",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2010-5326",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
