Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42855 | An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 16 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Dec 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability | |
| Title | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) | |
| Weaknesses | CWE-538 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-12-16T19:16:35.048Z
Reserved: 2024-09-27T20:05:49.543Z
Link: CVE-2024-47579
Updated: 2024-12-16T19:16:31.846Z
Status : Received
Published: 2024-12-10T01:15:05.817
Modified: 2024-12-10T01:15:05.817
Link: CVE-2024-47579
No data.
OpenCVE Enrichment
No data.
EUVD