Home / Vulnerabilities / CVE-2010-5326
CRITICAL SEVERITY
CVE-2010-5326 SAP · NetWeaver

SAP NetWeaver Remote Code Execution Vulnerability

Technical Severity

CVSS v3.1 Metrics

CRITICAL
10 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

16.90 %
Predictive Probability
Percentile Rank
94.8 th

Documented as more likely to be exploited than 94.8% of known CVEs.

Detection Date

Nov 03, 2021

Remediation Due

May 03, 2022

CISA Catalog Active

Threat Analysis

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence