CVE-2010-5326 describes an unauthenticated arbitrary code execution vulnerability in the Invoker Servlet of SAP NetWeaver Application Server Java platforms, affecting versions possibly before 7.3. This critical vulnerability (CVSS 10.0) allows remote attackers to execute code via HTTP/HTTPS requests due to a lack of authentication, leading to complete compromise of confidentiality, integrity, and availability. It has been actively exploited in the wild since at least 2013 as part of "Detour" attacks, with significant community discussion and media coverage, despite no public exploit code in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.30CPE matchmatch criteria | cpe:2.3:a:sap:netweaver_application_server_java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.