CVE-2024-47579 describes a critical vulnerability in SAP NetWeaver where an authenticated administrator can exploit an exposed webservice to read arbitrary files on the server. By uploading an internal file as a custom PDF font and then downloading it, an attacker can exfiltrate sensitive data. This medium-severity vulnerability has a CVSS score of 6.8, indicating high confidentiality impact with no integrity or availability compromise, and requires high privileges for exploitation. While no public exploit code or active exploitation has been observed, there is limited community discussion and media coverage, including a SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP NetWeaver AS For JAVA (Adobe Document Services) | ADSSSAP 7.50CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.