cbcvebase.
CVE-2010-5326
published 2016-05-13

CVE-2010-5326: The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to…

PriorityP190critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
17.45%
96.8th percentile
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

Affected

1 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_java<= 7.30

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2010-5326 exploits the SAP NetWeaver Invoker Servlet which does not require authentication; detect unauthenticated HTTP/HTTPS requests targeting the Invoker Servlet endpoint on SAP NetWeaver Application Server Java platforms (possibly before version 7.3)
  • This vulnerability was actively exploited in the wild between 2013 and 2016; threat hunting should include retrospective log review for SAP Invoker Servlet abuse during that period
  • FIN13 (Elephant Beetle) leveraged CVE-2010-5326 (SAP NetWeaver Invoker Servlet Exploit) for initial access; correlate SAP exploitation activity with follow-on web shell deployment (JspSpy, reGeorg, MiniWebCmdShell, Vonloesch Jsp File Browser 1.2) and lateral movement indicators
  • After exploiting CVE-2010-5326, FIN13 deployed obfuscated and open-source web shells on compromised web servers; monitor SAP application server directories for new JSP/WAR file drops, especially files masquerading as legitimate packages (e.g., wsexample.war, wsexamples.com, examples.war, exampl3s.war)
  • Post-exploitation of CVE-2010-5326 by FIN13 included masquerading WAR files; alert on WAR file deployments with names matching the pattern of legitimate SAP example packages
  • ·The vulnerable SAP NetWeaver version boundary is approximate; the NVD entry states 'possibly before 7.3', meaning the exact affected version range is not definitively confirmed in the source
  • ·The CISA KEV entry does not specify a precise affected version or patch identifier beyond directing to vendor instructions; consult SAP Security Note directly for authoritative patch guidance

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.