Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-47208

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-36104

Disclosure Date: June 04, 2024 (last updated February 14, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-25065

Disclosure Date: February 29, 2024 (last updated February 14, 2025)
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
0