CVE-2024-39847: Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2024-39847?
CVE-2024-39847 can lead to arbitrary file read vulnerabilities and server-side request forgery, allowing unauthenticated attackers to access sensitive files on the server.
Which versions of 4D Server are affected by CVE-2024-39847?
CVE-2024-39847 affects all versions of 4D Server that utilize the vulnerable XML parser functionality.
How do I fix CVE-2024-39847?
To address CVE-2024-39847, apply the latest security patches and updates provided by the vendor for 4D Server.
Can CVE-2024-39847 be exploited remotely?
Yes, CVE-2024-39847 can be exploited remotely by unauthenticated attackers via the SOAP endpoints.
What mitigation steps should be taken for CVE-2024-39847?
In addition to applying vendor patches, consider restricting access to SOAP endpoints and implementing input validation to mitigate the risk of CVE-2024-39847.