Apache Ofbiz vulnerabilities

54 known vulnerabilities affecting apache/ofbiz.

Total CVEs
54
CISA KEV
3
actively exploited
Public exploits
19
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH13MEDIUM16LOW2

Vulnerabilities

Page 3 of 3
CVE-2018-8033HIGHCVSS 7.5PoC≥ 16.11.01, ≤ 16.11.042018-12-13
CVE-2018-8033 [HIGH] CWE-200 CVE-2018-8033: In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEng In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by havi
nvd
CVE-2017-15714CRITICALCVSS 9.8v16.11.01v16.11.02+1 more2018-01-04
CVE-2017-15714 [CRITICAL] CWE-74 CVE-2017-15714: The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. Thi The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.
nvd
CVE-2012-1622CRITICALCVSS 9.8v10.042017-10-26
CVE-2012-1622 [CRITICAL] CVE-2012-1622: Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecifi Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2016-4462HIGHCVSS 8.8v11.04v11.04.01+16 more2017-08-30
CVE-2016-4462 [HIGH] CWE-20 CVE-2016-4462: By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Fre By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
nvd
CVE-2016-6800MEDIUMCVSS 6.1v11.04v11.04.01+16 more2017-08-30
CVE-2016-6800 [MEDIUM] CWE-79 CVE-2016-6800: The default configuration of the Apache OFBiz framework offers a blog functionality. Different users The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaS
nvd
CVE-2016-2170CRITICALCVSS 9.8≥ 12.04, < 12.04.06≥ 13.07, < 13.07.032016-04-12
CVE-2016-2170 [CRITICAL] CWE-20 CVE-2016-2170: Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute a Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
nvd
CVE-2015-3268MEDIUMCVSS 6.1v12.04.01v12.04.02+5 more2016-04-12
CVE-2015-3268 [MEDIUM] CWE-79 CVE-2015-3268: Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFor Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
nvd
CVE-2014-0232MEDIUMCVSS 4.3v12.04.01v12.04.02+5 more2014-08-22
CVE-2014-0232 [MEDIUM] CWE-79 CVE-2014-0232: Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages. Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1) result or (2) error message.
nvd
CVE-2012-1621MEDIUMCVSS 4.3v10.04.012014-06-19
CVE-2012-1621 [MEDIUM] CWE-79 CVE-2012-1621: Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3) mapKey parameter in a cms event request, which are not properly handled in an error message,
nvd
CVE-2013-0177LOWCVSS 3.5PoCv09.04v09.04.01+6 more2014-01-30
CVE-2013-0177 [LOW] CWE-79 CVE-2013-0177: Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apach Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the par
nvd
CVE-2013-2250CRITICALCVSS 10.0v10.04.01v10.04.02+6 more2013-08-15
CVE-2013-2250 [CRITICAL] CWE-20 CVE-2013-2250: Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, a Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.
nvd
CVE-2013-2137MEDIUMCVSS 4.3v10.04.01v10.04.02+6 more2013-08-15
CVE-2013-2137 [MEDIUM] CWE-79 CVE-2013-2137: Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apa Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-3506CRITICALCVSS 10.0v10.04.01v10.04.022012-10-25
CVE-2012-3506 [CRITICAL] CVE-2012-3506: Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.0 Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
nvd
CVE-2010-0432MEDIUMCVSS 4.3PoC≤ 09.042010-04-15
CVE-2010-0432 [MEDIUM] CWE-79 CVE-2010-0432: Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFB Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewpro
nvd