CVE-2006-5784

SAP Web Application Server <7.00 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5784. PoCs published by Nicob.

AI-analyzed exploit summary This Perl script exploits an information disclosure vulnerability in SAP Web Application Server Java 6.40 by sending crafted packets to 'enserver.exe' to download arbitrary files from the target system. The exploit leverages a protocol-level flaw to retrieve files up to 32KB in size.

Description

Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201. NOTE: this issue can be leveraged by local users to access a named pipe as the SAPServiceJ2E user.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nicob · perlremotewindows
https://www.exploit-db.com/exploits/3291

This Perl script exploits an information disclosure vulnerability in SAP Web Application Server Java 6.40 by sending crafted packets to 'enserver.exe' to download arbitrary files from the target system. The exploit leverages a protocol-level flaw to retrieve files up to 32KB in size.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: SAP Web Application Server Java 6.40
No auth needed
Prerequisites: Network access to the target SAP server on TCP port 3200+SYSNR · Knowledge of the target file path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29982
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1828
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4318
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20877
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/459499/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/450394/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3291
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22677
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1017628

Scores

EPSS 0.0289
EPSS Percentile 85.1%

Details

Status published
Products (2)
sap/sap_web_application_server 6.40
sap/sap_web_application_server 7.00
Published Nov 07, 2006
Tracked Since Feb 18, 2026