QID 150694
Date Published: 2023-06-23
QID 150694: Apache OFBiz: Arbitrary File Read Vulnerability (CVE-2022-47501)
Apache OFBiz is an open source enterprise resource planning system. It provides a suite of enterprise applications that integrate and automate many of the business processes of an enterprise.
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack.
Affected Versions:
Apache OFBiz: before 18.12.07.
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a OFBiz running on the target application.
Successful exploitation of the vulnerability may allow remote attackers to read sensitive files on the target server.
Solution
Customers are advised to upgrade to Apache OFBiz to latest version to remediate this vulnerability. For more information regarding this vulnerability please refer Apache OFBiz Advisory.
Vendor References
- Apache OFBiz -
lists.apache.org/thread/k8s76l0whydy45bfm4b69vq0mf94p3wc
CVEs related to QID 150694
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache OFBiz |
|