CVE-2006-5784: Medium severity SAP SAP Web Application Server vulnerability
Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201. NOTE: this issue can be leveraged by local users to access a named pipe as the SAPServiceJ2E user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5784?
CVE-2006-5784 is categorized as a vulnerability allowing unauthorized file access, posing a significant risk to affected systems.
How do I fix CVE-2006-5784?
To address CVE-2006-5784, apply the relevant patches for SAP Web Application Server 6.40 and 7.00 as specified by SAP.
Which versions are affected by CVE-2006-5784?
CVE-2006-5784 affects SAP Web Application Server versions 6.40 prior to patch 136 and 7.00 prior to patch 66.
How can CVE-2006-5784 be exploited?
CVE-2006-5784 can be exploited by remote attackers sending crafted data to specific TCP ports, allowing unauthorized file reading.
Is CVE-2006-5784 a local or remote vulnerability?
CVE-2006-5784 is a remote vulnerability that can also be leveraged by local users to gain unauthorized access.