CVE-2010-5326

CVSS 3.1 Score 10 of 10 (high)

Details

Published May 13, 2016
Updated: Dec 19, 2024

Summary

CVE-2010-5326 is a vulnerability affecting the Invoker Servlet on SAP NetWeaver Application Server Java platforms, potentially before version 7.3. This issue permits remote attackers to execute arbitrary code without requiring authentication, exploited in the wild between 2013 and 2016, leading to "Detour" attacks through HTTP or HTTPS requests.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SAP Netweaver Application Server Java
  • SAP Net Weaver

Affected Vendors

  • SAP SE