LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2010-5326: SAP NetWeaver Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2010-5326 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

CVE-2010-5326 is a remote code execution vulnerability in SAP NetWeaver Application Server Java Platforms. The Invoker Servlet does not require authentication, so an unauthenticated attacker can send an HTTP or HTTPS request that leads to code execution on the server. For IT and security teams running SAP landscapes, this matters because a successful exploit can give an outsider control of a core business application tier without valid credentials.

Public detail on the exact weakness class is limited beyond the unauthenticated Invoker Servlet behavior described by CISA. Confirm all version, configuration, and fix specifics against the vendor advisory before acting.

How it works

The flaw centers on the Invoker Servlet in SAP NetWeaver Application Server Java. That component accepts requests over HTTP or HTTPS and does not enforce authentication. An attacker who can reach the servlet can therefore invoke functionality that results in remote code execution on the host.

Because no authentication is required, the attack surface is any network path that can deliver a crafted request to the affected servlet endpoint. Exploitation does not depend on a prior foothold or stolen credentials; reachability alone is sufficient. Exact request format, payload construction, and any secondary conditions are not detailed in the provided facts and must be confirmed against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

SAP NetWeaver Application Server Java commonly runs as the foundation for SAP business applications, portals, and integration services in enterprise data centers and private clouds. Inventory every system that hosts NetWeaver Java stacks, including development, test, and production instances, plus any reverse proxies or load balancers that front them.

Because exact affected versions are not listed here, treat every NetWeaver Java deployment as potentially vulnerable until you verify its status against the vendor advisory.

How to remediate

Patch first. Apply the updates supplied by SAP for this vulnerability exactly as described in the vendor instructions; CISA’s required action is to apply updates per those instructions. After patching, restart services as directed and confirm the Invoker Servlet no longer accepts unauthenticated invocation.

Document the change and retain evidence of the applied update for audit and compliance purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls focused on the unauthenticated HTTP/HTTPS attack path.

These measures lower risk but do not replace the vendor patch; schedule the update as soon as operationally feasible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full system compromise and subsequent data theft or ransomware deployment; ransomware use specifically tied to this CVE is not documented in the provided facts. If you have reason to believe an unauthenticated request reached a vulnerable Invoker Servlet, treat the host as potentially compromised: isolate it, preserve forensic evidence, and begin incident-response procedures including credential rotation and integrity checks of critical SAP data. As a further step, you can run a free exposure scan of your email addresses against known breach datasets to determine whether associated credentials or personal data have appeared in prior public breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · NetWeaver
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities