Known Vulnerabilities for Ofbiz by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Ofbiz" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-23946 json | 5.3 - MEDIUM | 2024-02-29 | 2024-03-12 | |
| CVE-2023-51467 json | 9.8 - CRITICAL | 2023-12-26 | 2024-01-04 | |
| CVE-2023-50968 json | 7.5 - HIGH | 2023-12-26 | 2024-01-04 | |
| CVE-2023-46819 json | Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz... | 5.3 - MEDIUM | 2023-11-07 | 2023-11-14 |
| CVE-2022-47501 json | Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-a... | 7.5 - HIGH | 2023-04-14 | 2023-04-26 |
| CVE-2022-29158 json | Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs ... | 7.5 - HIGH | 2022-09-02 | 2023-07-21 |
| CVE-2022-29063 json | The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In vers... | 9.8 - CRITICAL | 2022-09-02 | 2022-09-08 |
| CVE-2022-25813 json | In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a... | 7.5 - HIGH | 2022-09-02 | 2022-09-07 |
| CVE-2022-25371 json | Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports... | 9.8 - CRITICAL | 2022-09-02 | 2024-01-25 |
| CVE-2022-25370 json | Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apa... | 5.4 - MEDIUM | 2022-09-02 | 2022-09-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Ofbiz | 9.04.02 | |||
| Application | Apache | Ofbiz | 9.04.01 | |||
| Application | Apache | Ofbiz | 9.04 | |||
| Application | Apache | Ofbiz | 17.12.04 | |||
| Application | Apache | Ofbiz | 17.12.03 | |||
| Application | Apache | Ofbiz | 17.12.01 | |||
| Application | Apache | Ofbiz | 16.11.07 | |||
| Application | Apache | Ofbiz | 16.11.06 | |||
| Application | Apache | Ofbiz | 16.11.05 | |||
| Application | Apache | Ofbiz | 16.11.04 | |||
| Application | Apache | Ofbiz | 16.11.03 | |||
| Application | Apache | Ofbiz | 16.11.02 | |||
| Application | Apache | Ofbiz | 16.11.01 | |||
| Application | Apache | Ofbiz | 13.07.03 | |||
| Application | Apache | Ofbiz | 13.07.02 | |||
| Application | Apache | Ofbiz | 13.07.01 | |||
| Application | Apache | Ofbiz | 13.07 | |||
| Application | Apache | Ofbiz | 12.04.06 | |||
| Application | Apache | Ofbiz | 12.04.05 | |||
| Application | Apache | Ofbiz | 12.04.04 |