Lucene search

K
cvelistApacheCVELIST:CVE-2016-4462
HistoryNov 29, 2016 - 12:00 a.m.

CVE-2016-4462

2016-11-2900:00:00
apache
www.cve.org

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.5%

By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01

CNA Affected

[
  {
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "13.07.*"
      },
      {
        "status": "affected",
        "version": "12.04.*"
      },
      {
        "status": "affected",
        "version": "11.04.*"
      }
    ]
  }
]

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.5%

Related for CVELIST:CVE-2016-4462