QID 730867
Date Published: 2023-08-10
QID 730867: Apache OFBiz XXE Vulnerability
The OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.
Affected Versions
Apache OFBiz 16.11.01 to 16.11.04
QID Detection Logic (un-authenticated) :
This QID seds xml payload in POST request to check for root string
On successful exploitation it allows an attacker to get secret information from the host.
Solution
Upgrade to 16.11.05. Refer to here for updates and patch information.
Vendor References
- CVE-2018-8033 -
ofbiz.apache.org/security.html
CVEs related to QID 730867
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache OFBiz |
|