CVE-2024-47579

CVSS V2 None CVSS V3 None
Description
An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability
Overview
  • CVE ID
  • CVE-2024-47579
  • Assigner
  • sap
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-10T00:12:05.039Z
  • Last Modified Date
  • 2024-12-10T00:12:05.039Z
History
Created Old Value New Value Data Type Notes
2024-12-10 13:46:28 Added to TrackCVE