๐Ÿ” CVE Alert

CVE-2024-39847

UNKNOWN 0.0

Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

CWE CWE-611
Vendor 4d
Product 4d server
Published Apr 30, 2026
Stay Ahead of the Next One

Get instant alerts for 4d 4d server

Be the first to know when new unknown vulnerabilities affecting 4d 4d server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

4D / 4D Server
* โ‰ค v20 R3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
schutzwerk.com: https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-002/ 4d.com: https://4d.com

Credits

Marcelo Reyes of SCHUTZWERK GmbH