VulnerabilityAnalyzed
CVE-2010-5326
SAP NetWeaver Remote Code Execution Vulnerability
KEVCRITICAL 10.0EPSS 17.4%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 17.45% probability · 97th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-306
- Affected
- sap/netweaver application server java
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-5326
References
- http://service.sap.com/sap/support/notes/1445998Permissions Required
- http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutionsBroken Link
- http://www.securityfocus.com/bid/48925Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/90533Third Party Advisory, VDB Entry
- http://www.us-cert.gov/ncas/alerts/TA16-132AThird Party Advisory, US Government Resource
- https://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applicationsThird Party Advisory
- http://service.sap.com/sap/support/notes/1445998Permissions Required
- http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutionsBroken Link
- http://www.securityfocus.com/bid/48925Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/90533Third Party Advisory, VDB Entry
- http://www.us-cert.gov/ncas/alerts/TA16-132AThird Party Advisory, US Government Resource
- https://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applicationsThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-5326US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.