Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-5326

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.264
EPSS Ranking 96.0%
CVSS Severity
CVSS v3 Score 10.0
CVSS v2 Score 10.0
Proposed Action
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Ransomware Campaign
Unknown
References
Products affected by CVE-2010-5326


Contact Us

Shodan ® - All rights reserved