VYPR

Ofbiz

by Apache

Source repositories

CVEs (76)

  • CVE-2024-38856CriKEVAug 5, 2024
    risk 0.80cvss 9.8epss 0.99

    Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some…

  • CVE-2024-32113CriKEVMay 8, 2024
    risk 0.80cvss 9.8epss 0.99

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

  • CVE-2021-26295CriMar 22, 2021
    risk 0.75cvss 9.8epss 0.98

    Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

  • CVE-2023-51467CriDec 26, 2023
    risk 0.74cvss 9.8epss 0.96

    The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

  • CVE-2023-49070CriDec 5, 2023
    risk 0.74cvss 9.8epss 0.95

    Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

  • CVE-2021-30128CriApr 27, 2021
    risk 0.70cvss 9.8epss 0.81

    Apache OFBiz has unsafe deserialization prior to 17.12.07 version

  • CVE-2021-29200CriApr 27, 2021
    risk 0.68cvss 9.8epss 0.55

    Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

  • CVE-2024-36104CriJun 4, 2024
    risk 0.66cvss 9.1epss 0.87

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

  • CVE-2019-0189CriSep 11, 2019
    risk 0.66cvss 9.8epss 0.24

    The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is…

  • CVE-2026-45434CriMay 19, 2026
    risk 0.65cvss 9.8epss 0.22

    Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

  • CVE-2016-2170CriApr 12, 2016
    risk 0.65cvss 9.8epss 0.13

    Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

  • CVE-2024-45507CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.93

    Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

  • CVE-2022-29063CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.04

    The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server…

  • CVE-2022-25371CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in…

  • CVE-2021-37608CriAug 18, 2021
    risk 0.64cvss 9.8epss 0.06

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at…

  • CVE-2019-10074CriSep 11, 2019
    risk 0.64cvss 9.8epss 0.03

    An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good…

  • CVE-2018-17200CriSep 11, 2019
    risk 0.64cvss 9.8epss 0.05

    The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream`…

  • CVE-2017-15714CriJan 4, 2018
    risk 0.64cvss 9.8epss 0.03

    The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.

  • CVE-2012-1622CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.05

    Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2024-25065CriFeb 29, 2024
    risk 0.63cvss 9.1epss 0.48

    Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Page 1 of 4