CVE-2006-6010
SAP Web Application Server - Information Disclosure via RFC_SYSTEM_INFO RfcCallReceive Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6010.
PoCs published by Agnivesh Sathasivam, nmonkee, ChrisJohnRiley, including Metasploit module auxiliary/scanner/sap/sap_soap_rfc_system_info.
AI-analyzed exploit summary This Metasploit module exploits the SAP SOAP RFC_SYSTEM_INFO function to gather sensitive system information such as OS version, SAP version, IP addresses, and other details via a crafted SOAP request. It requires authentication and targets the /sap/bc/soap/rfc endpoint.
Description
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnerability than CVE-2003-0747.
Exploits (1)
This Metasploit module exploits the SAP SOAP RFC_SYSTEM_INFO function to gather sensitive system information such as OS version, SAP version, IP addresses, and other details via a crafted SOAP request. It requires authentication and targets the /sap/bc/soap/rfc endpoint.