Unrated severityNVD Advisory· Published Sep 2, 2022· Updated Aug 3, 2024
Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz
CVE-2022-29063
Description
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.
Affected products
1- Range: Apache OFBiz
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.openwall.com/lists/oss-security/2022/09/02/6mitremailing-listx_refsource_MLIST
- lists.apache.org/thread/ytzrjc16pf357zntwk8tjby13kbx9105mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.