Skip to main content
Mallory
CriticalCISA KEVExploited in the wildPublic exploit

SAP NetWeaver Invoker Servlet Unauthenticated Remote Code Execution

IdentifiersCVE-2010-5326CWE-306· Missing Authentication for…

CVE-2010-5326 affects the Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before version 7.3. The servlet does not require authentication, allowing a remote attacker to invoke functionality over HTTP or HTTPS without prior login. According to the provided content, this exposure enables arbitrary code execution and was exploited in the wild between 2013 and 2016, including in activity referred to as a "Detour" attack. The core issue is an authentication bypass on a remotely reachable servlet that exposes dangerous server-side invocation capability.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the SAP NetWeaver AS Java host. This can provide full compromise of the affected application server, including deployment of web shells or malicious applications, execution of system commands, persistence, credential theft, and use of the server as an initial access point for broader lateral movement within the environment.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, disable the Invoker Servlet if it is not required, or restrict access to it through strong authentication and network-layer controls. Limit HTTP/HTTPS exposure of SAP NetWeaver AS Java systems to trusted management networks, place the service behind filtering or reverse proxy controls, and monitor for suspicious requests to servlet endpoints, unexpected code execution, and unauthorized application deployment. Conduct threat hunting for persistence mechanisms such as web shells and rogue WAR files.

Remediation

Patch, then assume compromise.

Upgrade SAP NetWeaver Application Server Java to a fixed release that removes or properly restricts unauthenticated access to the Invoker Servlet; the provided content indicates affected platforms are possibly before 7.3. If vendor fixes are available, apply the relevant SAP security updates and verify that the Invoker Servlet is disabled or access-controlled. Review deployed applications and server logs for evidence of prior exploitation, especially unauthorized servlet invocation, malicious WAR deployment, or web shell placement.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
SAPNetweaver Application Server Javaapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence2

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.

SAP NetWeaver Invoker Servlet Unauthenticated Remote Code Execution (CVE-2010-5326) | Mallory