CVE-2022-47501
published 2023-04-14CVE-2022-47501: Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue…
PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
10.18%
95.1th percentile
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a
pre-authentication attack.
This issue affects Apache OFBiz: before 18.12.07.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 18.12.07 | 18.12.07 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | >= 18.12.06 < 18.12.07 | 18.12.07 |
Detection & IOCsextracted from sources · hover to see the quote
url/solr/solrdefault/debug/dump?param=ContentStreams&stream.url=file://{{path}}
path/etc/passwd
pathc:/windows/win.ini
- →Detect exploitation attempts by monitoring GET requests to the Solr debug dump endpoint containing a 'stream.url=file://' parameter, indicating a local file inclusion attempt via the Solr plugin.
- →On Linux targets, a successful exploit response body will match the regex pattern 'root:.*:0:0:' (contents of /etc/passwd), with HTTP 200 status.
- →On Windows targets, a successful exploit response body will contain 'bit app support', 'fonts', and 'extensions' (contents of win.ini), with HTTP 200 status.
- →Identify Apache OFBiz instances via Shodan using the query html:"OFBiz" or http.html:"ofbiz", or by the presence of the ofbiz.visitor= cookie.
- →Identify Apache OFBiz instances via FOFA using the query app="Apache_OFBiz", body="ofbiz", or app="apache_ofbiz".
- →This is a pre-authentication (unauthenticated) attack; no session or credentials are required to exploit the vulnerability. ↗
- ·The vulnerability only affects Apache OFBiz instances with the Solr plugin enabled. Instances without the Solr plugin are not exploitable via this vector. ↗
- ·Only Apache OFBiz versions before 18.12.07 are affected. The fix was introduced in version 18.12.07 via commit 582add7d3. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vulncheck7.5HIGH
vendor_apache7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-raspi-5.4 vulnerabilities
osv·2025-01-06·CVSS 5.5
linux-raspi-5.4 vulnerabilities
linux-raspi-5.4 vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- S390 architecture;
- x86 architecture;
- Power management core;
- GPU drivers;
- InfiniBand drivers;
- Network drivers;
- S/390 drivers;
- TTY drivers;
- BTRFS file system;
- EROFS file system;
- F2FS file system;
- File systems infrastructure;
- BPF subsystem;
- Socket messages infrastructure;
- Bluetooth subsystem;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- SELinux security module;
(CVE-2022-48938, CVE-2024-42156, CVE-2024-36953, CVE-2024-38538,
CVE-2021-47501, CVE-2024-42068, CVE-2024-26947, CVE-2024-46724,
CVE-2024-
OSV
linux-iot vulnerabilities
osv·2024-12-20·CVSS 5.5
linux-iot vulnerabilities
linux-iot vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- S390 architecture;
- x86 architecture;
- Power management core;
- GPU drivers;
- InfiniBand drivers;
- Network drivers;
- S/390 drivers;
- TTY drivers;
- BTRFS file system;
- EROFS file system;
- F2FS file system;
- File systems infrastructure;
- BPF subsystem;
- Socket messages infrastructure;
- Bluetooth subsystem;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- SELinux security module;
(CVE-2022-48938, CVE-2024-42156, CVE-2024-36953, CVE-2024-38538,
CVE-2021-47501, CVE-2024-42068, CVE-2024-26947, CVE-2024-46724,
CVE-2024-36968,
OSV
linux-aws, linux-aws-5.4 vulnerabilities
osv·2024-12-17·CVSS 5.5
linux-aws, linux-aws-5.4 vulnerabilities
linux-aws, linux-aws-5.4 vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- S390 architecture;
- x86 architecture;
- Power management core;
- GPU drivers;
- InfiniBand drivers;
- Network drivers;
- S/390 drivers;
- TTY drivers;
- BTRFS file system;
- EROFS file system;
- F2FS file system;
- File systems infrastructure;
- BPF subsystem;
- Socket messages infrastructure;
- Bluetooth subsystem;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- SELinux security module;
(CVE-2022-48938, CVE-2024-42156, CVE-2024-36953, CVE-2024-38538,
CVE-2021-47501, CVE-2024-42068, CVE-2024-26947, CVE-2024-46724,
OSV
linux-bluefield, linux-oracle, linux-oracle-5.4 vulnerabilities
osv·2024-12-17·CVSS 5.5
linux-bluefield, linux-oracle, linux-oracle-5.4 vulnerabilities
linux-bluefield, linux-oracle, linux-oracle-5.4 vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- S390 architecture;
- x86 architecture;
- Power management core;
- GPU drivers;
- InfiniBand drivers;
- Network drivers;
- S/390 drivers;
- TTY drivers;
- BTRFS file system;
- EROFS file system;
- F2FS file system;
- File systems infrastructure;
- BPF subsystem;
- Socket messages infrastructure;
- Bluetooth subsystem;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- SELinux security module;
(CVE-2022-48938, CVE-2024-42156, CVE-2024-36953, CVE-2024-38538,
CVE-2021-47501, CVE-2024-42068, CVE-2024-
GHSA
GHSA-mxw6-c2fh-2h9w: Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin
ghsa_unreviewed·2023-07-06
CVE-2022-47501 [HIGH] CWE-22 GHSA-mxw6-c2fh-2h9w: Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a
pre-authentication attack.
This issue affects Apache OFBiz: before 18.12.07.
VulnCheck
Apache OFBiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2022·CVSS 7.5
CVE-2022-47501 [HIGH] Apache OFBiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Apache OFBiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a
pre-authentication attack.
This issue affects Apache OFBiz: before 18.12.07.
Affected: Apache OFBiz
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://app.crowdsec.net/cti/cve-explorer/CVE-2022-47501
Apache
Apache ofbiz: CVE-2022-47501
vendor_apache·CVSS 7.5
CVE-2022-47501 [HIGH] Apache ofbiz: CVE-2022-47501
Apache ofbiz: CVE-2022-47501
; affected releases before 18.12.07; fixed in 18.12.07 with commit 582add7d3
No detection rules found.
Nuclei
Apache OFBiz < 18.12.07 - Local File Inclusion
nuclei·CVSS 7.5
CVE-2022-47501 [HIGH] Apache OFBiz < 18.12.07 - Local File Inclusion
Apache OFBiz < 18.12.07 - Local File Inclusion
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
Template:
id: CVE-2022-47501
info:
name: Apache OFBiz < 18.12.07 - Local File Inclusion
author: your3cho
severity: high
description: |
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
impact: |
Unauthenticated attackers can read arbitrary files from the server filesystem through the Solr plugin debug endpoint in Apache OFBiz, potentially accessing configuration files, credentials, and other sensitive syst
http://www.openwall.com/lists/oss-security/2023/04/18/5http://www.openwall.com/lists/oss-security/2023/04/18/9http://www.openwall.com/lists/oss-security/2023/04/19/1http://www.openwall.com/lists/oss-security/2023/04/19/6https://lists.apache.org/thread/k8s76l0whydy45bfm4b69vq0mf94p3wchttps://ofbiz.apache.org/download.htmlhttps://ofbiz.apache.org/security.htmlhttp://www.openwall.com/lists/oss-security/2023/04/18/5http://www.openwall.com/lists/oss-security/2023/04/18/9http://www.openwall.com/lists/oss-security/2023/04/19/1http://www.openwall.com/lists/oss-security/2023/04/19/6https://lists.apache.org/thread/k8s76l0whydy45bfm4b69vq0mf94p3wchttps://ofbiz.apache.org/download.htmlhttps://ofbiz.apache.org/security.html
2023-04-14
Published
Exploited in the wild