Apache

Ofbiz

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.53%
  • Veröffentlicht 15.07.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 05:02:09

IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

  • EPSS 2.18%
  • Veröffentlicht 30.04.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:22:48

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

Exploit
  • EPSS 26.02%
  • Veröffentlicht 30.04.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:16:33

Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

  • EPSS 86.81%
  • Veröffentlicht 01.04.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:11:40

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

  • EPSS 3.02%
  • Veröffentlicht 06.02.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:22:49

an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06

  • EPSS 2.13%
  • Veröffentlicht 26.11.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 01:30:49

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be ...

  • EPSS 2.44%
  • Veröffentlicht 11.09.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:20

An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should...

  • EPSS 3.54%
  • Veröffentlicht 11.09.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:20

The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 18605...

  • EPSS 30.51%
  • Veröffentlicht 11.09.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:16:26

The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request para...

  • EPSS 2.97%
  • Veröffentlicht 11.09.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 03:54:04

The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it usi...