Vulnerability record · CVE-2010-5326 · published 13 May 2016
CVE-2010-5326: SAP NetWeaver Java Invoker Servlet unauthenticated remote code execution
Sap · Netweaver Application Server Java
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attackers to execute arbitrary code over HTTP or HTTPS. The flaw was exploited in the wild from 2013 through 2016 as the "Detour" attack, and it remains in CISA's Known Exploited Vulnerabilities catalog.
Description
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS 10.0 score, confirmed in-the-wild exploitation and CISA KEV listing.
What it is
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, allowing remote attackers to execute arbitrary code over HTTP or HTTPS. The flaw was exploited in the wild from 2013 through 2016 as the "Detour" attack, and it remains in CISA's Known Exploited Vulnerabilities catalog.
Impact
An unauthenticated remote attacker can execute arbitrary code on the SAP Java application server, gaining full control of the host and any data or downstream systems it can reach. CVSS 3.1 scores it 10.0 with scope change, reflecting complete confidentiality, integrity and availability loss.
Attack surface
Reachable over the network via HTTP or HTTPS requests to the exposed Invoker Servlet; the CVSS vector shows no privileges required and no user interaction. Any internet- or network-exposed SAP Java stack with the servlet enabled is a candidate.
Exploitation
Confirmed exploited in the wild (2013-2016) and listed in CISA KEV since 2021-11-03; EPSS 30-day probability is about 17.5 percent (96.97th percentile). No ransomware campaign use is documented in this record.
What to do
- Apply the SAP security note 1445998 updates or upgrade NetWeaver Application Server Java to a fixed release, per vendor instructions.
- Disable or block the Invoker Servlet if it is not required for business operations.
- Restrict network access to SAP Java HTTP/HTTPS ports so only trusted hosts and management networks can reach them.
- Monitor SAP Java stack logs and web access logs for requests to the Invoker Servlet and investigate any unexpected ones.
- Verify remediation against CISA KEV due date requirements and track completion.
Detection
- Search web and reverse-proxy logs for requests to the Invoker Servlet path and flag any that originate outside expected management networks.
- Alert on unexpected child processes or command execution spawned by the SAP Java server process.
- Monitor for outbound connections from SAP Java hosts to unfamiliar external addresses, which may indicate post-exploitation activity.
- Review SAP security audit logs for authentication bypass or servlet access anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-5326 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP NetWeaver Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-5326 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-5326), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.