logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2010-5326

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2010-5326

Description:
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
Last updated date:
04/20/2021

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
04/20/2021
Reference url to background

https://nvd.nist.gov/vuln/detail/CVE-2010-5326

Type:
exploitation
Confidence:
HIGH
Date of publishing:
07/23/2021
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy