1889Third-party advisory
http://securityreason.com/securityalert/1889 CVE-2006-6010
SAP /sap/bc/soap/rfc SOAP Service RFC_SYSTEM_INFO Function Sensitive Information Gathering
Record summary
CVE-2006-6010 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnerability than CVE-2003-0747.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitSAP /sap/bc/soap/rfc SOAP Service RFC_SYSTEM_INFO Function Sensitive Information GatheringMetasploit auxiliary PoCby Agnivesh Sathasivam +2 moreNot analyzed1 file
References
420061112 Old SAP exploitsmailing list
http://www.securityfocus.com/archive/1/451378/100/0/threaded netweaver-rfcsysteminfo-info-disclosure(39997)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39997 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-6010