HIGH
Apache OFBiz: Arbitrary file reading vulnerability
Published Apr 14, 2023
7.5
HIGHCVSS 3.1
EPSS 10.18%
Description
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
Affected products
-
- Version 18.12.06StatusaffectedConstraints<18.12.07
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache OFBiz | affected |
|
-
- Version 0StatusaffectedConstraints<18.12.07
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to release 18.12.07
Weaknesses (1)
References (8)
- http://www.openwall.com/lists/oss-security/2023/04/18/5 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/04/18/9 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/04/19/1 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/04/19/6 Mailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-50262 Advisory
- https://lists.apache.org/thread/k8s76l0whydy45bfm4b69vq0mf94p3wc vendor-advisoryVendor Advisory
- https://ofbiz.apache.org/download.html release-notesVendor Advisory
- https://ofbiz.apache.org/security.html relatedVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2023/04/18/5 | Mailing ListThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2023/04/18/9 | Mailing ListThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2023/04/19/1 | Mailing ListThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2023/04/19/6 | Mailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-50262 | Advisory | |
| https://lists.apache.org/thread/k8s76l0whydy45bfm4b69vq0mf94p3wc | vendor-advisoryVendor Advisory | |
| https://ofbiz.apache.org/download.html | release-notesVendor Advisory | |
| https://ofbiz.apache.org/security.html | relatedVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 14, 2023
Updated Feb 13, 2025
Reserved Dec 15, 2022
Link CVE-2022-47501
CISA Vulnrichment
Updated Oct 17, 2024
ENISA EUVD
EUVD-2022-50262 Assigner apache
Published Apr 14, 2023
Updated Feb 13, 2025
Exploited since n/a
Link EUVD-2022-50262