Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-39847

Опубликовано: 30 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:4d:server:20:r3:*:*:*:*:*:*
cpe:2.3:a:4d:server:20:r4:*:*:*:*:*:*
cpe:2.3:a:4d:server:20:r6:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00447
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
github
5 месяцев назад

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

EPSS

Процентиль: 37%
0.00447
Низкий

7.5 High

CVSS3

Дефекты

CWE-611