ZeroHour

CVE-2010-5326

KEVlarge

Unauthenticated Remote Code Execution in SAP NetWeaver Invoker Servlet

CISA: SAP NetWeaver Remote Code Execution Vulnerability

CVSS
EPSS
17%p97
Published
KEV added
AI analysis

The Invoker Servlet in SAP NetWeaver Application Server (AS) Java does not require authentication, which allows unauthenticated attackers to trigger remote code execution on the server. The flaw is triggered by sending a crafted HTTP or HTTPS request to the exposed Invoker Servlet on an affected NetWeaver AS Java system, with no credentials required. Successful exploitation gives an attacker the ability to run arbitrary code on the SAP application server, typically at the privileges of the application service, exposing business data and enabling further attacks into the environment. Any organization running SAP NetWeaver with the Java application server stack — particularly instances reachable from the internet or untrusted networks — is affected. Exploitation is confirmed in the wild: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), EPSS estimates a 17.4% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept code is known.

What to do: Inventory all SAP NetWeaver AS Java instances and prioritize internet-exposed ones for remediation, applying SAP's updates per vendor instructions as required by the CISA KEV entry. Until patched, require authentication for or restrict access to the Invoker Servlet and limit HTTP/HTTPS access to the AS Java ports to trusted networks, then verify the fix is in place.

Affected
SAP NetWeaver (Application Server Java platforms — Invoker Servlet)
Estimated exposure
largetens of thousands of internet-exposed SAP NetWeaver AS Java systems (10k–100k order of magnitude) — Public internet scans regularly surface on the order of 10,000–100,000 exposed SAP NetWeaver endpoints, and the AS Java stack is a common component of SAP's very large enterprise installed base, so tens of thousands of exposed, affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

CISA Known Exploited Vulnerability
Affected
SAP NetWeaver
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
SAP
Products
NetWeaver

In the news