Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz
Description
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Apache OFBiz prior to 18.12.06 allows unauthenticated remote code execution via a path traversal vulnerability in the Birt viewer component.
Vulnerability
Apache OFBiz versions prior to 18.12.06 include the Birt viewer component (version 4.5.0) which contains a path traversal vulnerability [2][3]. This flaw allows an attacker to bypass intended access controls and read or write arbitrary files on the server. The vulnerability is triggered through the Birt plugin's handling of report resources, enabling remote code execution when combined with file upload capabilities.
Exploitation
An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests to the Birt viewer endpoint [1][2]. The path traversal allows the attacker to write malicious files (e.g., JSP) to the web application directory, which can then be executed by the server. No authentication or user interaction is required, making the attack straightforward for anyone with network access to the OFBiz instance.
Impact
Successful exploitation results in remote code execution with the privileges of the OFBiz application server [1][2]. This can lead to full compromise of the affected system, including data theft, modification, and denial of service. The vulnerability is rated High severity.
Mitigation
The Apache OFBiz project has released version 18.12.06, which disables the Birt component entirely as the upstream Birt project did not provide a fix [1][2][3]. Users should upgrade to OFBiz 18.12.06 or apply the patches referenced in the Apache JIRA issue [2]. There is no other workaround; disabling the Birt component manually is recommended if upgrade is not immediately possible. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: Apache OFBiz
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.openwall.com/lists/oss-security/2022/09/02/7mitremailing-listx_refsource_MLIST
- www.openwall.com/lists/oss-security/2022/09/03/1mitremailing-listx_refsource_MLIST
- www.openwall.com/lists/oss-security/2022/09/08/2mitremailing-listx_refsource_MLIST
- lists.apache.org/thread/bvp3sczqq863lxr1wh7wjvdtjbkcwspqmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.