An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.
History

Mon, 16 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Dec 2024 00:45:00 +0000

Type Values Removed Values Added
Description An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.
Title Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)
Weaknesses CWE-538
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-12-16T19:16:09.928Z

Reserved: 2024-09-27T20:05:49.543Z

Link: CVE-2024-47580

cve-icon Vulnrichment

Updated: 2024-12-10T21:10:42.212Z

cve-icon NVD

Status : Received

Published: 2024-12-10T01:15:05.973

Modified: 2024-12-10T01:15:05.973

Link: CVE-2024-47580

cve-icon Redhat

No data.