Skip to content
COOEY

EXPOSURES › CVE-2010-5326

CVE-2010-5326

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-5326 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

SAP NetWeaver's unauthenticated Invoker Servlet allowed remote code execution via HTTP/HTTPS requests.

An unauthenticated Invoker Servlet in SAP NetWeaver enabled remote code execution without requiring authentication, allowing attackers to execute arbitrary code via HTTP or HTTPS requests. DIB organizations must ensure SAP NetWeaver systems are patched and monitored for unauthenticated endpoints, as this vulnerability could lead to full system compromise and data exfiltration. The lack of authentication on a critical servlet is a severe design flaw that bypasses standard access controls.

Shame score — SAP shipped an unauthenticated remote code execution vulnerability in a widely deployed enterprise platform, enabling attackers to execute arbitrary code without any authentication, which is a severe and avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
SAP faced severe criticism for a critical remote code execution vulnerability in NetWeaver that lacked authentication, exposing systems to unauthenticated remote code execution via HTTP/HTTPS requests
cooey ↗ severe-fallout -0.80
SAP was heavily criticized for the unauthenticated Invoker Servlet vulnerability allowing remote code execution, highlighting a severe security oversight in NetWeaver.
"SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized