CVE-2024-39847
📛 CVE Title
Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP
Description
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- SCHUTZWERK
- CVSS severity
- HIGH
- CVSS score
- 8.7 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y- Effective score
- 8.7 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-611 - Reserved
- 2024-06-29
- Published
- 2026-04-30 09:10 UTC
- Last updated
- 2026-04-30 15:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/39xxx/CVE-2024-39847.json
- Linked Threat
- CVE-2024-39847 — CVE-2024-39847
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-55562 - Assigner
- SCHUTZWERK
- Published
- Apr 30, 2026, 7:10:17 AM
- Updated
- May 17, 2026, 10:18:39 PM
- EUVD base score (CVSS 4.0)
-
8.7 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y - EUVD-reported EPSS
- 0.0200
- Vendors
- 4D
- Products
-
4D Server4D Server (* ≤v20 R3)
ENISA description: Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
EUVD references (2)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| 4D | 4D Server |
* (affected),
v20 R4 (unknown),
v20 R7 (unaffected)
|
Windows |
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (25)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:vulners.com
CVE - 2024 -38474 affects Apache HTTP Server's mod_rewrite: substitutions that capture and substitute unsafely can be mis-encoded, enabling unintended access paths. The issue is fixed by upgrading to Apache HTTP Server 2.4.60 (and related advisories ...
2026-07-28 01:37 UTC -
web:www.forbes.com
Microsoft Exchange users are urged to mitigate a zero-day vulnerability that CISA has confirmed is under active exploitation.
2026-07-28 01:37 UTC -
web:cybersecuritynews.com
Microsoft has released its June 2026 Patch Tuesday security updates, addressing a hefty 198 vulnerabilities across its product ecosystem. The June rollout, published on June 9, 2026, stands out not only for its volume but also for the inclusion of three zero-day vulnerabilities that were actively exploited or publicly known before a fix was available. Administrators are urged to prioritize ...
2026-07-28 01:37 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-07-28 01:37 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-07-28 01:37 UTC -
web:my.f5.com
CVE - 2024 -38474 Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture ...
2026-07-28 01:37 UTC -
web:nvd.nist.gov
Description Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and ...
2026-07-28 01:37 UTC -
web:source.android.com
This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.
2026-05-22 09:58 UTC -
web:nvd.nist.gov
Official websites use .gov A .gov website belongs to an official government organization in the United States.
2026-05-22 09:58 UTC -
web:www.bleepingcomputer.com
Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates.
2026-05-22 09:58 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-22 09:58 UTC -
web:cyberinsider.com
Google has released Chrome 148, one of the largest security update batches in the browser's history, patching 127 vulnerabilities.
2026-05-22 09:58 UTC -
web:petri.com
If a Group Policy setting is available to roll back a fix , it is included in the Windows Update KB article and release notes as a mitigation for a known issue.
2026-05-22 09:58 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 09:58 UTC -
web:cyberpress.org
The third vulnerability, CVE -2026-44791 (GHSA-wrwr-h859-xh2r), is particularly alarming because it represents a patch bypass. It circumvents the previously issued fix for GHSA-hqr4-h3xv-9m3r in the XML node, reintroducing prototype pollution through a different code path. When chained with additional nodes, this too can escalate to RCE on the host.
2026-05-22 09:58 UTC -
web:www.virustotal.com
Streamline your investigations with Google Threat Intelligence Agentic and the new Dark Web (DDW) module. Perform hunting and pivoting across forums using natural language or specific modifiers. Bridge threat actor identities and map global operations easy.
2026-05-22 04:08 UTC -
web:cybersecuritynews.com
Fortinet released a sweeping batch of security advisories on April 14, 2026, addressing 11 vulnerabilities spanning multiple product lines, including two rated Critical, two rated High, and seven rated Medium or Low.
2026-05-22 04:08 UTC -
web:robertsspaceindustries.com
Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...
2026-05-22 04:08 UTC -
web:ubuntu.com
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use. Get Ubuntu Pro 30-day free trial
2026-05-22 04:08 UTC -
web:www.nist.gov
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.
2026-05-22 04:08 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 04:08 UTC -
web:www.sentinelone.com
CVE - 2024 -38474 is a remote code execution vulnerability in Apache HTTP Server. Learn about its impact, affected versions, and mitigation methods.
2026-05-22 04:08 UTC -
web:www.suse.com
Secure your Linux systems from CVE - 2024 -38474. Stay ahead of potential threats with the latest security updates from SUSE.
2026-05-22 04:08 UTC -
web:www.threatclaw.ai
ThreatClaw assigns CVE-2024-39847 an exploitation risk score of 27/100 with high confidence. CVE-2024-39847 scores 27/100 driven by limited public signal data. Given this profile, standard patching cadence applies for affected systems. Monitor for new developments and patch at your standard cadence.
2026-05-22 04:08 UTC -
web:app.opencve.io
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute ...
2026-05-22 04:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-39847.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-39847",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-04-30T13:00:30.372326Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-04-30T13:00:38.371Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"modules": [
"4D Web Server"
],
"platforms": [
"Windows"
],
"product": "4D Server",
"vendor": "4D",
"versions": [
{
"lessThanOrEqual": "v20 R3",
"status": "affected",
"version": "*",
"versionType": "custom"
},
{
"lessThanOrEqual": "v20 R6",
"status": "unknown",
"version": "v20 R4",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "v20 R7",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:4d:4d_server:*:*:windows:*:*:*:*:*",
"versionEndIncluding": "v20_r3",
"versionStartIncluding": "*",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:4d:4d_server:v20_r7:*:windows:*:*:*:*:*",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Marcelo Reyes of SCHUTZWERK GmbH"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.<br>"
}
],
"value": "Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services."
}
],
"impacts": [
{
"capecId": "CAPEC-664",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-664 Server Side Request Forgery"
}
]
},
{
"capecId": "CAPEC-497",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-497 File Discovery"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "YES",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-611",
"description": "CWE-611 Improper Restriction of XML External Entity Reference",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-30T07:10:17.999Z",
"orgId": "23637b5d-af4c-4cf9-b8f6-deb7fd0f8423",
"shortName": "SCHUTZWERK"
},
"references": [
{
"url": "https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-002/"
},
{
"tags": [
"product"
],
"url": "https://4d.com"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update to 4D Server 20 R7 or higher."
}
],
"value": "Update to 4D Server 20 R7 or higher."
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2024-06-17T11:00:00.000Z",
"value": "Vulnerability discovered"
},
{
"lang": "en",
"time": "2024-06-24T11:00:00.000Z",
"value": "Attempt to contact vendor, no response received"
},
{
"lang": "en",
"time": "2024-06-25T11:00:00.000Z",
"value": "CVE ID requested"
},
{
"lang": "en",
"time": "2024-06-29T14:59:00.000Z",
"value": "CVE-2024-39847 assigned"
},
{
"lang": "en",
"time": "2024-07-04T11:00:00.000Z",
"value": "Attempt to contact vendor again, no response received"
},
{
"lang": "en",
"time": "2024-07-09T11:00:00.000Z",
"value": "Attempt to contact vendor again, no response received"
},
{
"lang": "en",
"time": "2024-07-16T11:00:00.000Z",
"value": "Attempt to contact vendor again, no response received"
},
{
"lang": "en",
"time": "2024-07-22T11:00:00.000Z",
"value": "Attempt to contact vendor again, no response received"
},
{
"lang": "en",
"time": "2026-04-29T11:00:00.000Z",
"value": "Advisory published"
}
],
"title": "Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "23637b5d-af4c-4cf9-b8f6-deb7fd0f8423",
"assignerShortName": "SCHUTZWERK",
"cveId": "CVE-2024-39847",
"datePublished": "2026-04-30T07:10:17.999Z",
"dateReserved": "2024-06-29T20:55:54.740Z",
"dateUpdated": "2026-04-30T13:00:38.371Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}