CVE-2006-6010: Medium severity sap sap web application server vulnerability
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFCSYSTEMINFO RfcCallReceive request, a different vulnerability than CVE-2003-0747.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6010?
CVE-2006-6010 has a medium severity level due to the risk of information disclosure.
How does CVE-2006-6010 affect SAP Web Application Server?
CVE-2006-6010 allows remote attackers to extract sensitive information, including operating system and SAP version details.
How can I remediate CVE-2006-6010?
To fix CVE-2006-6010, restrict access to the RFC_SYSTEM_INFO function and implement appropriate network security controls.
What versions of SAP Web Application Server are affected by CVE-2006-6010?
CVE-2006-6010 affects all versions of SAP Web Application Server that are configured to allow remote function calls.
Is CVE-2006-6010 related to any other vulnerabilities?
CVE-2006-6010 is a distinct vulnerability and should not be confused with CVE-2003-0747, as it involves a different attack vector.