Back

HIGH

Apache OFBiz: Arbitrary file reading vulnerability

Published Apr 14, 2023

Description

Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.

Affected products

Remediation

Vendor solution

Upgrade to release 18.12.07

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 14, 2023
Updated Feb 13, 2025
Reserved Dec 15, 2022
CISA Vulnrichment
Updated Oct 17, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Apr 14, 2023
Updated Feb 13, 2025
Exploited since n/a
EUVD-2022-50262