Description
ERPScan discovered a vulnerability in SAP NetWeaver that allows remote code execution via operating system commands through the SAP ConfigServlet without any authentication.
Remediation
Install SAP security patches 1467771, 1445998.
Change the value of EnableInvokerServletGlobally property of servlet_jsp service on the server nodes to false.
References
Related Vulnerabilities
WordPress Plugin Advanced Access Manager Arbitrary Code Execution (2.8.2)
AjaxPro.NET Professional Deserialization RCE (CVE-2021-23758)
Remote code execution in bootstrap-sass 3.2.0.3
Python object deserialization of user-supplied data
WordPress Plugin EWWW Image Optimizer Remote Code Execution (2.8.3)