SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  SAP NetWeaver Detour Authentication Bypass

Category: WEB-ATTACKS      

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via crafted request, aka a "Detour" attack.


Relevant Information