# CVE-2024-47579

## Summary

- **CVE ID:** CVE-2024-47579
- **Severity:** MEDIUM
- **CVSS Score:** 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-538
- **Published:** Dec 10, 2024
- **Last Modified:** Mar 13, 2026

## Description

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server.  Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability

## Affected Products

- SAP_SE — SAP NetWeaver AS for JAVA (Adobe Document Services) (ADSSSAP 7.50)

## References

- [CNA](https://me.sap.com/notes/3536965)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.54%
- **EPSS Percentile:** 43.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._