CVE-2022-29063
published 2022-09-02CVE-2022-29063: The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.72%
88.6th percentile
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 18.12.06 | 18.12.06 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | Apache OFBiz – 18.12.05 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for outbound or loopback RMI connections to localhost:1099 initiated by the Apache OFBiz Solr plugin process, especially at server start-up or restart, which may indicate exploitation of a malicious local RMI server. ↗
- →Flag Apache OFBiz instances running versions at or before 18.12.05 as vulnerable; look for the absence of commit 061252a80 to identify unpatched deployments. ↗
- ·The malicious RMI server must be hosted on localhost (127.0.0.1), meaning the attacker requires local access or the ability to bind a service on the loopback interface of the target server prior to OFBiz start-up or restart. ↗
- ·Exploitation window is limited to server start-up or restart events, not continuous runtime; detection strategies should account for this timing constraint. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_apache9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache ofbiz: CVE-2022-29063
vendor_apache·CVSS 9.8
CVE-2022-29063 [CRITICAL] Apache ofbiz: CVE-2022-29063
Apache ofbiz: CVE-2022-29063
; affected releases before 18.12.06; fixed in 18.12.06 with commit 061252a80
GHSA
GHSA-5qfw-44p9-rc2g: The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099
ghsa_unreviewed·2022-09-03
CVE-2022-29063 [CRITICAL] CWE-502 GHSA-5qfw-44p9-rc2g: The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-02
Published