CISA Known Exploited Vulnerability

CVE-2010-5326

SAP · NetWeaver

SAP NetWeaver Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

Required action

Apply updates per vendor instructions.