CVE-2024-39847: Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP

Published Apr 30, 2026
·
Updated

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Affected Software

4 affected components
4d 4D Server
4d Server=20-r3
4d Server=20-r4
4d Server=20-r6

Remediation

Information

Update to 4D Server 20 R7 or higher.

Event History

Apr 30, 2026
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What are the potential impacts of CVE-2024-39847?

CVE-2024-39847 can lead to arbitrary file read vulnerabilities and server-side request forgery, allowing unauthenticated attackers to access sensitive files on the server.

2

Which versions of 4D Server are affected by CVE-2024-39847?

CVE-2024-39847 affects all versions of 4D Server that utilize the vulnerable XML parser functionality.

3

How do I fix CVE-2024-39847?

To address CVE-2024-39847, apply the latest security patches and updates provided by the vendor for 4D Server.

4

Can CVE-2024-39847 be exploited remotely?

Yes, CVE-2024-39847 can be exploited remotely by unauthenticated attackers via the SOAP endpoints.

5

What mitigation steps should be taken for CVE-2024-39847?

In addition to applying vendor patches, consider restricting access to SOAP endpoints and implementing input validation to mitigate the risk of CVE-2024-39847.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203