JustAppSec
HIGH SeverityCVSS 4.08.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y

CVE-2024-39847

Last updated Apr 30, 2026 · Published Apr 30, 2026

← Back to list

Description

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Affected products

1 listed
  • 4D:4D Server

Mappings

CWE

CWE-611

CAPEC

CAPEC-497CAPEC-664

Related


CVE® content © MITRE Corporation. Licensed under the CVE Terms of Use. Terms

Need help?Get in touch.