CVE-2024-25065
- EPSS 1.05%
- Published 29.02.2024 01:44:14
- Last modified 05.05.2025 21:02:31
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
CVE-2024-23946
- EPSS 3.64%
- Published 29.02.2024 01:44:11
- Last modified 21.11.2024 08:58:44
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
CVE-2023-51467
- EPSS 94%
- Published 26.12.2023 15:15:08
- Last modified 21.11.2024 08:38:11
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
CVE-2023-50968
- EPSS 81.59%
- Published 26.12.2023 12:15:07
- Last modified 21.11.2024 08:37:38
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recomme...
CVE-2023-49070
- EPSS 93.89%
- Published 05.12.2023 08:15:07
- Last modified 13.02.2025 18:15:40
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
CVE-2023-46819
- EPSS 0.3%
- Published 07.11.2023 11:15:10
- Last modified 21.11.2024 08:29:22
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09. Users are recommended to upgrade to version 18.12.09
CVE-2022-47501
- EPSS 83.49%
- Published 14.04.2023 16:15:07
- Last modified 13.02.2025 17:15:49
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
CVE-2022-29158
- EPSS 0.45%
- Published 02.09.2022 07:15:07
- Last modified 21.11.2024 06:58:36
Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OF...
CVE-2022-29063
- EPSS 13.42%
- Published 02.09.2022 07:15:07
- Last modified 21.11.2024 06:58:26
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server st...
CVE-2022-25813
- EPSS 51.57%
- Published 02.09.2022 07:15:07
- Last modified 21.11.2024 06:53:02
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communicat...