Server-Side Request Forgery (SSRF) in SAP NetWeaver AS JAVA - CVE-2024-47579

 

Server-Side Request Forgery (SSRF) in SAP NetWeaver AS JAVA - CVE-2024-47579

Published: December 10, 2024


Vulnerability identifier: #VU101369
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-47579
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote user to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input within the Adobe Document Service. A remote user with administrator privileges can send a specially crafted HTTP request and download or rewrite contents of arbitrary files on the system via the upload and download features.



Affected software

SAP NetWeaver AS JAVA

How to mitigate CVE-2024-47579

Install updates from vendor's website.


External References

Related Security Bulletins