Looking for the vulnerability index of Invicti's legacy products?
SAP NetWeaver ConfigServlet remote command execution - Vulnerability Database

SAP NetWeaver ConfigServlet remote command execution

Description

ERPScan discovered a vulnerability in SAP NetWeaver that allows remote code execution via operating system commands through the SAP ConfigServlet without any authentication.

Remediation

Install SAP security patches 1467771, 1445998. <br/> Change the value of <strong><span class="bb-dark">EnableInvokerServletGlobally</span></strong> property of servlet_jsp service on the server nodes to <strong><span class="bb-dark">false</span></strong>.

Related Vulnerabilities