CVE-2024-47578 CRITICAL

CVE-2024-47578: Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)

Vendor Sap_Se
Product SAP NetWeaver AS for JAVA (Adobe Document Services)
Weakness CWE-918 · SSRF
Published December 10, 2024
Last update December 10, 2024

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

Description

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.

Key dates

Disclosure timeline

December 10, 2024 CVE published
December 10, 2024 Record updated