Lucene search

K
cve[email protected]CVE-2022-25371
HistorySep 02, 2022 - 7:15 a.m.

CVE-2022-25371

2022-09-0207:15:07
CWE-22
web.nvd.nist.gov
37
8
apache ofbiz
rce
birt plugin
cve-2022-25371
data visualizations
reports
remote code execution
nvd
security vulnerability

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.025 Low

EPSS

Percentile

90.2%

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.

Affected configurations

Vulners
NVD
Node
apacheofbizRange≀18.12.05
CPENameOperatorVersion
apache:ofbizapache ofbizlt18.12.06

CNA Affected

[
  {
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "18.12.05",
        "status": "affected",
        "version": "Apache OFBiz",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.025 Low

EPSS

Percentile

90.2%

Related for CVE-2022-25371