CVE-2010-5326: SAP NetWeaver Remote Code Execution Vulnerability
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Other sources
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5326?
CVE-2010-5326 is considered critical due to its capability to allow remote code execution without authentication.
How do I fix CVE-2010-5326?
To mitigate CVE-2010-5326, it is recommended to disable the Invoker Servlet or to update to a version of SAP NetWeaver Application Server Java that is later than 7.30.
What systems are affected by CVE-2010-5326?
CVE-2010-5326 affects SAP NetWeaver Application Server Java versions up to and including 7.30.
What are the potential impacts of CVE-2010-5326?
CVE-2010-5326 can lead to unauthorized access and manipulation of systems, resulting in data breaches and system compromise.
Is CVE-2010-5326 being actively exploited?
Yes, there have been reports indicating that CVE-2010-5326 is actively being exploited in the wild.