Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-01012
HistoryDec 28, 2023 - 12:00 a.m.

Apache OFBiz Server-Side Request Forgery Vulnerability

2023-12-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
apache ofbiz
ssrf
vulnerability
file attribute
attacker
exploit
java-based
erp
system
web application

6.8 Medium

AI Score

Confidence

High

0.29 Low

EPSS

Percentile

96.9%

Apache OFBiz is the United States Apache (Apache) Foundation of a set of enterprise resource planning (ERP) system. The system provides a set of Java-based Web application components and tools. Apache OFBiz suffers from a server-side request forgery vulnerability that can be exploited by an attacker to conduct an SSRF attack by sending a specially crafted request to read arbitrary file attributes.

CPENameOperatorVersion
apache ofbizlt18.12.11

6.8 Medium

AI Score

Confidence

High

0.29 Low

EPSS

Percentile

96.9%

Related for CNVD-2024-01012