cbcvebase.
CVE-2024-47580
published 2024-12-10

CVE-2024-47580: An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an…

PriorityP434medium6.8CVSS 3.1
AVNACLPRHUINSCCHINAN
EPSS
0.52%
40.8th percentile
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_netweaver_as_for_java
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.