EXPOSURES › CVE-2010-5326
CVE-2010-5326
HIGH ⌖ ON CISA KEV · EXPLOITEDSAP NetWeaver's unauthenticated Invoker Servlet allowed remote code execution via HTTP/HTTPS requests.
An unauthenticated Invoker Servlet in SAP NetWeaver enabled remote code execution without requiring authentication, allowing attackers to execute arbitrary code via HTTP or HTTPS requests. DIB organizations must ensure SAP NetWeaver systems are patched and monitored for unauthenticated endpoints, as this vulnerability could lead to full system compromise and data exfiltration. The lack of authentication on a critical servlet is a severe design flaw that bypasses standard access controls.
Shame score — SAP shipped an unauthenticated remote code execution vulnerability in a widely deployed enterprise platform, enabling attackers to execute arbitrary code without any authentication, which is a severe and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
"SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request."
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |