← Back

CVE-2024-39847

nvd nist
Published: Apr 30, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:XShow less
Source: 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423 (Secondary)

Description

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Affected (3)

Products: 4d: Server
1 product
Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
4d
Version 20 r3
Version 20 r4
Version 20 r6

References (3)

Source: 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423
Product
Source: 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.