cbcvebase.
CVE-2022-25371
published 2022-09-02

CVE-2022-25371: Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.06%
89.5th percentile
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 18.12.0618.12.06
apacheofbiz
apache_software_foundationapache_ofbizApache OFBiz – 18.12.05

Detection & IOCsextracted from sources · hover to see the quote

  • Apache OFBiz RCE via Birt plugin; versions 18.12.05 and earlier are vulnerable (CVE-2022-25371). The fix was introduced in version 18.12.08 with commit 41ff12cf8 — detect exploitation attempts targeting Birt report/data-visualization endpoints on OFBiz instances running 18.12.07 or earlier.
  • ·CVE-2022-25371 affects Apache OFBiz release 18.12.05 and earlier (NVD) / 18.12.07 (Apache security page); the fix is in 18.12.08 (commit 41ff12cf8). The two sources cite different affected versions — ensure your asset inventory checks both 18.12.05 and 18.12.07 as potentially vulnerable.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_apache9.8CRITICAL
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.