Vulnerabilities > Apache > Ofbiz > 17.12.01

DATE CVE VULNERABILITY TITLE RISK
2021-03-22 CVE-2021-26295 Deserialization of Untrusted Data vulnerability in Apache Ofbiz
Apache OFBiz has unsafe deserialization prior to 17.12.06.
network
low complexity
apache CWE-502
critical
9.8
2020-07-15 CVE-2020-13923 Authorization Bypass Through User-Controlled Key vulnerability in Apache Ofbiz
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
network
low complexity
apache CWE-639
5.3
2020-04-30 CVE-2019-12425 Injection vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
network
low complexity
apache CWE-74
7.5
2020-04-30 CVE-2019-0235 Cross-Site Request Forgery (CSRF) vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
network
low complexity
apache CWE-352
8.8