Description
ERPScan discovered a vulnerability in SAP NetWeaver that allows remote code execution via operating system commands through the SAP ConfigServlet without any authentication.
Remediation
Install SAP security patches 1467771, 1445998.
Change the value of EnableInvokerServletGlobally property of servlet_jsp service on the server nodes to false.
References
Related Vulnerabilities
WordPress Plugin is_human() 'type' Parameter Remote Command Injection (1.4.2)
WordPress Plugin VaultPress Man-in-The-Middle (MiTM) Remote Code Execution (1.8.6)
Drupal Core 8.4.x Remote Code Execution (8.4.0 - 8.4.5)
Apache HTTP Server Insecure Path Normalization (CVE-2021-41773, CVE-2021-42013)
WordPress Plugin WP-Syntax Remote PHP Code Execution (0.9.9)