Vulnerabilities > Apache > Ofbiz > 16.11.03

DATE CVE VULNERABILITY TITLE RISK
2018-12-13 CVE-2018-8033 Information Exposure vulnerability in Apache Ofbiz
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint.
network
low complexity
apache CWE-200
7.5
2018-01-04 CVE-2017-15714 Injection vulnerability in Apache Ofbiz 16.11.01/16.11.02/16.11.03
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed.
network
low complexity
apache CWE-74
7.5