CVE-2007-6509

Appian Enterprise BPM <5.6 SP1 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-6509. PoCs published by Chris Castaldo, including Metasploit module auxiliary/dos/windows/appian/appian_bpm.

AI-analyzed exploit summary This exploit is a crafted packet designed to trigger a denial-of-service (DoS) condition in Appian BPMS 5.6 SP1. The packet contains specific byte sequences that cause the application to crash when processed.

Description

Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Chris Castaldo · textdosmultiple
https://www.exploit-db.com/exploits/30896

This exploit is a crafted packet designed to trigger a denial-of-service (DoS) condition in Appian BPMS 5.6 SP1. The packet contains specific byte sequences that cause the application to crash when processed.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Appian Business Process Management Suite (BPMS) 5.6 SP1
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/appian/appian_bpm.rb

This Metasploit module exploits a denial of service vulnerability in Appian Enterprise Business Suite 5.6 SP1 by sending a malformed packet to TCP port 5400, causing the service to crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Appian Enterprise Business Suite 5.6 SP1
No auth needed
Prerequisites: Network access to TCP port 5400 on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=119794961212714&w=2
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28121
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/39500
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39145
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26913

Scores

EPSS 0.7553
EPSS Percentile 98.9%

Details

CWE
CWE-20
Status published
Products (1)
appian/business_process_management_suite 5.6 sp1
Published Dec 21, 2007
Tracked Since Feb 18, 2026