CVE-2010-5326
published 2016-05-13CVE-2010-5326: The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to…
PriorityP190critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
17.45%
96.8th percentile
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_java | <= 7.30 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2010-5326 exploits the SAP NetWeaver Invoker Servlet which does not require authentication; detect unauthenticated HTTP/HTTPS requests targeting the Invoker Servlet endpoint on SAP NetWeaver Application Server Java platforms (possibly before version 7.3) ↗
- →This vulnerability was actively exploited in the wild between 2013 and 2016; threat hunting should include retrospective log review for SAP Invoker Servlet abuse during that period ↗
- →FIN13 (Elephant Beetle) leveraged CVE-2010-5326 (SAP NetWeaver Invoker Servlet Exploit) for initial access; correlate SAP exploitation activity with follow-on web shell deployment (JspSpy, reGeorg, MiniWebCmdShell, Vonloesch Jsp File Browser 1.2) and lateral movement indicators
- →After exploiting CVE-2010-5326, FIN13 deployed obfuscated and open-source web shells on compromised web servers; monitor SAP application server directories for new JSP/WAR file drops, especially files masquerading as legitimate packages (e.g., wsexample.war, wsexamples.com, examples.war, exampl3s.war)
- →Post-exploitation of CVE-2010-5326 by FIN13 included masquerading WAR files; alert on WAR file deployments with names matching the pattern of legitimate SAP example packages
- ·The vulnerable SAP NetWeaver version boundary is approximate; the NVD entry states 'possibly before 7.3', meaning the exact affected version range is not definitively confirmed in the source ↗
- ·The CISA KEV entry does not specify a precise affected version or patch identifier beyond directing to vendor instructions; consult SAP Security Note directly for authoritative patch guidance ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SAP Netweaver Java Application Server up to 7.2 Invoker Servlet Detour privileges management (ID 12834 / BID-48925)
vuldb·2026-04-23·CVSS 10.0
CVE-2010-5326 [CRITICAL] SAP Netweaver Java Application Server up to 7.2 Invoker Servlet Detour privileges management (ID 12834 / BID-48925)
A vulnerability labeled as critical has been found in SAP Netweaver Java Application Server up to 7.2. Impacted is an unknown function of the component Invoker Servlet. Such manipulation leads to improper privilege management (Detour).
This vulnerability is documented as CVE-2010-5326. The attack can be executed remotely. Additionally, an exploit exists.
GHSA
GHSA-w5jq-q2q7-wx7x: The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7
ghsa_unreviewed·2022-05-13
CVE-2010-5326 [CRITICAL] CWE-306 GHSA-w5jq-q2q7-wx7x: The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
VulnCheck
SAP NetWeaver Remote Code Execution Vulnerability
vulncheck·2010·CVSS 10.0
CVE-2010-5326 [CRITICAL] SAP NetWeaver Remote Code Execution Vulnerability
SAP NetWeaver Remote Code Execution Vulnerability
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Affected: SAP NetWeaver
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2010-5326; https://f.hubspotusercontent30.net/hubfs/8776530/Sygnia-%20Elephant%20Beetle_Jan2022.pdf; https://digital.nhs.uk/cyber-alerts/2021/cc-3815; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.csoonline.com/article/3674119/most-common-sap-vulnerabilities-attackers-try-to-exploit.html; https://www.csoonline.com/article/2092336/sap-users-are-at-high-risk-as-hackers-exploit-application-vu
CISA
SAP NetWeaver Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 10.0
CVE-2010-5326 [CRITICAL] SAP NetWeaver Remote Code Execution Vulnerability
Vulnerability: SAP NetWeaver Remote Code Execution Vulnerability
Affected: SAP NetWeaver
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-5326
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Threat Intel
FIN13 (FIN13, Elephant Beetle)
threat_intel·CVSS 10.0
[CRITICAL] FIN13 (FIN13, Elephant Beetle)
# Threat Actor Profile: FIN13
ATT&CK ID: G1016
Also known as: FIN13, Elephant Beetle
## Overview
FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.(Citation: Mandiant FIN13 Aug 2022)(Citation: Sygnia Elephant Beetle Jan 2022)
## Techniques (TTPs)
### Reconnaissance
- T1589 Gather Victim Identity Information
Usage: FIN13 has researched employees to target for social engineering attacks.(Citation: Mandiant FIN13 Aug 2022)
- T1590.004 Network Topology
Usage: FIN13 has searched for infrastructure that can provide remote access to an environment for targ
http://service.sap.com/sap/support/notes/1445998http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutionshttp://www.securityfocus.com/bid/48925http://www.securityfocus.com/bid/90533http://www.us-cert.gov/ncas/alerts/TA16-132Ahttps://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applicationshttp://service.sap.com/sap/support/notes/1445998http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutionshttp://www.securityfocus.com/bid/48925http://www.securityfocus.com/bid/90533http://www.us-cert.gov/ncas/alerts/TA16-132Ahttps://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applicationshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-5326
2016-05-13
Published
2021-11-03
Added to CISA KEV
Exploited in the wild