The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HSap Netweaver Application Server Java
APPSap≤ 7.30
CISA KEV — detailsi
- Vendori
- SAP
- Producti
- NetWeaver
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
Apply updates per vendor instructions.
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Related vulnerabilities
SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard
SQL Injection w serwerze UDDI SAP NetWeaver J2EE Engine 7.40
SAP NetWeaver AS Java – command injection przez upload pliku w Log Viewer
SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation
SAP NetWeaver AS Java — nieautoryzowane wykonanie kodu przez błąd bufora HTTP