# CVE-2010-5326

## Summary

- **CVE ID:** CVE-2010-5326
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** May 13, 2016
- **Last Modified:** Sep 16, 2026

## Description

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.securityfocus.com/bid/90533)
- [CNA](https://www.onapsis.com/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applications)
- [CNA](http://service.sap.com/sap/support/notes/1445998)
- [CNA](http://www.onapsis.com/research/publications/sap-security-in-depth-vol4-the-invoker-servlet-a-dangerous-detour-into-sap-java-solutions)
- [CNA](http://www.us-cert.gov/ncas/alerts/TA16-132A)
- [CNA](http://www.securityfocus.com/bid/48925)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-5326)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 16.90%
- **EPSS Percentile:** 94.8

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Nov 3, 2021
- **Due Date:** May 3, 2022

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._