Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5jq-q2q7-wx7x

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

EPSS

Процентиль: 95%
0.16904
Средний

10 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 10
nvd
больше 9 лет назад

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

CVSS3: 10
fstec
больше 9 лет назад

Уязвимость компонента Invoker Servlet сервера веб-приложений SAP NetWeaver Java Application Server, позволяющая нарушителю выполнить произвольный код или получить полный контроль над системой

EPSS

Процентиль: 95%
0.16904
Средний

10 Critical

CVSS3

Дефекты

CWE-306