Lucene search

K
cvelistApacheCVELIST:CVE-2021-37608
HistoryAug 18, 2021 - 7:50 a.m.

CVE-2021-37608 Arbitrary file upload vulnerability in OFBiz

2021-08-1807:50:12
CWE-434
apache
www.cve.org
1

9.7 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.2%

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.

CNA Affected

[
  {
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "17.12.07",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

References

9.7 High

AI Score

Confidence

High

0.018 Low

EPSS

Percentile

88.2%

Related for CVELIST:CVE-2021-37608