HIGH SeverityCVSS 4.08.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y
CVE-2024-39847
Last updated Apr 30, 2026 · Published Apr 30, 2026
Description
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
Affected products
1 listed- 4D:4D Server
Mappings
CWE
CWE-611
CAPEC
CAPEC-497CAPEC-664
Related
CVE® content © MITRE Corporation. Licensed under the CVE Terms of Use. Terms
