CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2010-5326

CVSS 10.0v3.1pub. 2016-05-13upd. 2026-04-22

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Sap Netweaver Application Server Java

    APP
    Sap
    ≤ 7.30

CISA KEV — detailsi

Vendori
SAP
Producti
NetWeaver
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
May 3, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 maja 2022
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2020-6287CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard

CVE-2016-2386CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w serwerze UDDI SAP NetWeaver J2EE Engine 7.40

CVE-2024-22127CRITICAL9.1PL ✓same product

SAP NetWeaver AS Java – command injection przez upload pliku w Log Viewer

CVE-2023-40309CRITICAL9.8PL ✓same product

SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation

CVE-2022-22532CRITICAL9.8PL ✓same product

SAP NetWeaver AS Java — nieautoryzowane wykonanie kodu przez błąd bufora HTTP