CVE-2010-5326
קריטית 10.0 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- SAP NetWeaver Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
מדדים
- CVSS 3.1
-
10.0 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 17% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-306
מוצרים מושפעים
sap: netweaver application server java
קישורים
- http://service.sap.com/sap/support/notes/1445998 Permissions Required
- http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-in… Broken Link
- http://www.securityfocus.com/bid/48925 Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/90533 Third Party AdvisoryVDB Entry
- http://www.us-cert.gov/ncas/alerts/TA16-132A Third Party AdvisoryUS Government Resource
- https://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-atta… Third Party Advisory
- http://service.sap.com/sap/support/notes/1445998 Permissions Required
- http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-in… Broken Link
- http://www.securityfocus.com/bid/48925 Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/90533 Third Party AdvisoryVDB Entry