CVE-2010-5326
KEVlargeUnauthenticated Remote Code Execution in SAP NetWeaver Invoker Servlet
CISA: SAP NetWeaver Remote Code Execution Vulnerability
The Invoker Servlet in SAP NetWeaver Application Server (AS) Java does not require authentication, which allows unauthenticated attackers to trigger remote code execution on the server. The flaw is triggered by sending a crafted HTTP or HTTPS request to the exposed Invoker Servlet on an affected NetWeaver AS Java system, with no credentials required. Successful exploitation gives an attacker the ability to run arbitrary code on the SAP application server, typically at the privileges of the application service, exposing business data and enabling further attacks into the environment. Any organization running SAP NetWeaver with the Java application server stack — particularly instances reachable from the internet or untrusted networks — is affected. Exploitation is confirmed in the wild: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), EPSS estimates a 17.4% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept code is known.
What to do: Inventory all SAP NetWeaver AS Java instances and prioritize internet-exposed ones for remediation, applying SAP's updates per vendor instructions as required by the CISA KEV entry. Until patched, require authentication for or restrict access to the Invoker Servlet and limit HTTP/HTTPS access to the AS Java ports to trusted networks, then verify the fix is in place.
| SAP NetWeaver (Application Server Java platforms — Invoker Servlet) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
- Affected
- SAP NetWeaver
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- SAP
- Products
- NetWeaver