Executive brief
The Invoker Servlet in SAP NetWeaver Application Server Java platforms does not require authentication. This allows unauthenticated remote attackers to execute arbitrary code via specially crafted HTTP or HTTPS requests.
Affected products
- SAP NetWeaver Application Server Java up to and including 7.30
Timeline
- 2013: exploited: Exploitation in the wild reported between 2013 and 2016.
- 2016-05-13: disclosed: NVD Published Date.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.