SAP NetWeaver ConfigServlet remote command execution
Description
ERPScan discovered a vulnerability in SAP NetWeaver that allows remote code execution via operating system commands through the SAP ConfigServlet without any authentication.
Remediation
Install SAP security patches 1467771, 1445998. <br/> Change the value of <strong><span class="bb-dark">EnableInvokerServletGlobally</span></strong> property of servlet_jsp service on the server nodes to <strong><span class="bb-dark">false</span></strong>.