# CVE-2024-39847

> Vulnerability · severity: **HIGH** (CVSS 7.5).

## Description

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

## Key facts

- **CVE ID:** CVE-2024-39847
- **Published:** 2026-04-30
- **CVSS severity:** HIGH
- **CVSS base score:** 7.5
- **CWE codes:** CWE-611

## Affected products

- `4d:server`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-39847

## Citation

> AI Analytics. CVE-2024-39847. Retrieved 2026-07-23 from https://api.ai-analytics.org/cve/CVE-2024-39847. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*