Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
References
| Link | Resource |
|---|---|
| https://4d.com | Product |
| https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-002/ | Exploit Third Party Advisory |
| http://seclists.org/fulldisclosure/2026/May/0 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-30 07:16
Updated : 2026-06-17 07:42
NVD link : CVE-2024-39847
Mitre link : CVE-2024-39847
CVE.ORG link : CVE-2024-39847
JSON object : View
Products Affected
4d
- server
CWE
CWE-611
Improper Restriction of XML External Entity Reference
