Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 4 |
CVE-ID | CVE-2024-47582 CVE-2024-47580 CVE-2024-47579 CVE-2024-47578 |
CWE-ID | CWE-776 CWE-918 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
SAP NetWeaver AS JAVA Server applications / Application servers |
Vendor | SAP |
Security Bulletin
This security bulletin contains information about 4 vulnerabilities.
EUVDB-ID: #VU101371
Risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-47582
CWE-ID:
CWE-776 - Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of XML input. A remote non-authenticated attacker can pass specially crafted XML input to the application and perform XML entity expansion attack, leading to a denial of service condition.
Install updates from vendor's website.
Vulnerable software versionsSAP NetWeaver AS JAVA: 7.50
CPE2.3 External linkshttps://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2024.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU101370
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-47580
CWE-ID:
CWE-918 - Server-Side Request Forgery (SSRF)
Exploit availability: No
DescriptionThe disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied
input within the Adobe Document Service. A remote user with
administrator privileges can use an exposed webservice to create a PDF with an embedded attachment, attach an arbitrary file on the system and later download that file.
Install updates from vendor's website.
Vulnerable software versionsSAP NetWeaver AS JAVA: 7.50
CPE2.3 External linkshttps://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2024.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU101369
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-47579
CWE-ID:
CWE-918 - Server-Side Request Forgery (SSRF)
Exploit availability: No
DescriptionThe disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied
input within the Adobe Document Service. A remote user with
administrator privileges can send a specially crafted HTTP request and download or rewrite contents of arbitrary files on the system via the upload and download features.
Install updates from vendor's website.
Vulnerable software versionsSAP NetWeaver AS JAVA: 7.50
CPE2.3 External linkshttps://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2024.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU101368
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-47578
CWE-ID:
CWE-918 - Server-Side Request Forgery (SSRF)
Exploit availability: No
DescriptionThe disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the Adobe Document Service. A remote user with administrator privileges can send a specially crafted HTTP request and trick the application into reading or writing files.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsSAP NetWeaver AS JAVA: 7.50
CPE2.3 External linkshttps://support.sap.com/en/my-support/knowledge-base/security-notes-news/december-2024.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.