The Invoker Servlet on SAP NetWeaver Application Server...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 7, 2025
Description
Published by the National Vulnerability Database
May 13, 2016
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 7, 2025
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
References