Back

CRITICAL KEV

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack

Published May 13, 2016 ·Due May 3, 2022

Description

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 13, 2016
Updated Oct 21, 2025
Reserved May 12, 2016
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a