peter bassill · operator
$ cve CVE-2006-5784 JSON

CVE-2006-5784 EXPLOIT

4.6
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201. NOTE: this issue can be leveraged by local users to access a named pipe as the SAPServiceJ2E user.

Scoring

CVSS4.6 (MEDIUM, v2.0)
VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS2.92% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2006-11-07
Last modified2026-06-16

Affected (1)

VendorProduct
sapsap web application server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD