← Vulnerability feed

Vulnerability record · CVE-2010-5326 · published 13 May 2016

CVE-2010-5326: SAP NetWeaver Java Invoker Servlet unauthenticated remote code execution

Sap · Netweaver Application Server Java

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attackers to execute arbitrary code over HTTP or HTTPS. The flaw was exploited in the wild from 2013 through 2016 as the "Detour" attack, and it remains in CISA's Known Exploited Vulnerabilities catalog.

10.0 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 18% · top 2.9% CWE-306 · Missing authentication for critical function
10.0CVSS 3.1 base score, v2 10.0
18%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References
16 Jun 2026Last modified by NVD

Description

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS 10.0 score, confirmed in-the-wild exploitation and CISA KEV listing.

What it is

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attackers to execute arbitrary code over HTTP or HTTPS. The flaw was exploited in the wild from 2013 through 2016 as the "Detour" attack, and it remains in CISA's Known Exploited Vulnerabilities catalog.

Impact

An unauthenticated remote attacker can execute arbitrary code on the SAP Java application server, gaining full control of the host and any data or downstream systems it can reach. CVSS 3.1 scores it 10.0 with scope change, reflecting complete confidentiality, integrity and availability loss.

Attack surface

Reachable over the network via HTTP or HTTPS requests to the exposed Invoker Servlet; the CVSS vector shows no privileges required and no user interaction. Any internet- or network-exposed SAP Java stack with the servlet enabled is a candidate.

Exploitation

Confirmed exploited in the wild (2013-2016) and listed in CISA KEV since 2021-11-03; EPSS 30-day probability is about 17.5 percent (96.97th percentile). No ransomware campaign use is documented in this record.

What to do

  • Apply the SAP security note 1445998 updates or upgrade NetWeaver Application Server Java to a fixed release, per vendor instructions.
  • Disable or block the Invoker Servlet if it is not required for business operations.
  • Restrict network access to SAP Java HTTP/HTTPS ports so only trusted hosts and management networks can reach them.
  • Monitor SAP Java stack logs and web access logs for requests to the Invoker Servlet and investigate any unexpected ones.
  • Verify remediation against CISA KEV due date requirements and track completion.

Detection

  • Search web and reverse-proxy logs for requests to the Invoker Servlet path and flag any that originate outside expected management networks.
  • Alert on unexpected child processes or command execution spawned by the SAP Java server process.
  • Monitor for outbound connections from SAP Java hosts to unfamiliar external addresses, which may indicate post-exploitation activity.
  • Review SAP security audit logs for authentication bypass or servlet access anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-5326 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP NetWeaver Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-5326 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-6287SAP NetWeaver AS Java LM Configuration Wizard missing authenticationThe SAP NetWeaver AS Java LM Configuration Wizard fails to perform an authentication check, allowing an unauthenticated attacker to execute configura…KEVEPSS 95%analysed9.8CVE-2016-2386SAP NetWeaver UDDI Server SQL InjectionThe UDDI server in SAP NetWeaver J2EE Engine 7.40 is vulnerable to SQL injection through unspecified vectors, allowing arbitrary SQL command executio…KEVEPSS 72%analysed7.5CVE-2017-12637SAP NetWeaver Java directory traversal allows arbitrary file readSAP NetWeaver Application Server Java 7.5 contains a directory traversal flaw in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS. A remote attack…KEVEPSS 95%analysed7.5CVE-2016-3976SAP NetWeaver AS Java directory traversal in CrashFileDownloadServletSAP NetWeaver Application Server Java 7.1 through 7.5 contains a directory traversal flaw in the fileName parameter of CrashFileDownloadServlet. A re…KEVEPSS 47%analysed6.5CVE-2016-9563SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpointThe BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~t…KEVEPSS 24%analysed5.3CVE-2016-2388SAP NetWeaver AS Java Universal Worklist information disclosureThe Universal Worklist Configuration in SAP NetWeaver AS Java 7.4 exposes sensitive user information to a crafted HTTP request. The flaw is an inform…KEVEPSS 52%analysed10.0CVE-2020-26829Sap netweaver application server java missing authentication for critical function vulnerabilitySAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…EPSS 4.8%9.8CVE-2023-40309Sap commoncryptolib incorrect authorization vulnerabilitySAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2010-5326), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.