Vulnerabilities > Apache > Ofbiz

DATE CVE VULNERABILITY TITLE RISK
2020-07-15 CVE-2020-9496 Deserialization of Untrusted Data vulnerability in Apache Ofbiz 17.12.03
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
network
low complexity
apache CWE-502
6.1
2020-07-15 CVE-2020-13923 Authorization Bypass Through User-Controlled Key vulnerability in Apache Ofbiz
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
network
low complexity
apache CWE-639
5.3
2020-04-30 CVE-2019-12425 Injection vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
network
low complexity
apache CWE-74
7.5
2020-04-30 CVE-2019-0235 Cross-Site Request Forgery (CSRF) vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
network
low complexity
apache CWE-352
8.8
2020-04-01 CVE-2020-1943 Cross-site Scripting vulnerability in Apache Ofbiz
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
network
low complexity
apache CWE-79
6.1
2020-02-06 CVE-2019-12426 Unspecified vulnerability in Apache Ofbiz
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
network
low complexity
apache
5.3
2019-11-26 CVE-2011-3600 XXE vulnerability in Apache Ofbiz
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem.
network
low complexity
apache CWE-611
7.5
2019-09-11 CVE-2019-10074 Improper Encoding or Escaping of Output vulnerability in Apache Ofbiz
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field.
network
low complexity
apache CWE-116
critical
9.8
2019-09-11 CVE-2019-10073 Cross-site Scripting vulnerability in Apache Ofbiz
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks.
network
low complexity
apache CWE-79
6.1
2019-09-11 CVE-2019-0189 Deserialization of Untrusted Data vulnerability in Apache Ofbiz
The java.io.ObjectInputStream is known to cause Java serialisation issues.
network
low complexity
apache CWE-502
critical
9.8