#VU101369 Server-Side Request Forgery (SSRF) in SAP NetWeaver AS JAVA - CVE-2024-47579
Published: December 10, 2024
SAP NetWeaver AS JAVA
SAP
Description
The disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied
input within the Adobe Document Service. A remote user with
administrator privileges can send a specially crafted HTTP request and download or rewrite contents of arbitrary files on the system via the upload and download features.