#VU101370 Server-Side Request Forgery (SSRF) in SAP NetWeaver AS JAVA - CVE-2024-47580
Published: December 10, 2024
SAP NetWeaver AS JAVA
SAP
Description
The disclosed vulnerability allows a remote user to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied
input within the Adobe Document Service. A remote user with
administrator privileges can use an exposed webservice to create a PDF with an embedded attachment, attach an arbitrary file on the system and later download that file.