SB2016041222 - Multiple vulnerabilities in OFBiz
Published: April 12, 2016 Updated: December 27, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2016-2170)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
2) Cross-site scripting (CVE-ID: CVE-2015-3268)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 when processing description attribute of a display-entity element. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
Install update from vendor's website.
References
- http://ofbiz.apache.org/download.html#vulnerabilities
- http://packetstormsecurity.com/files/136639/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html
- http://www.securityfocus.com/archive/1/538034/100/0/threaded
- http://www.securitytracker.com/id/1035513
- https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04
- https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07
- https://cwiki.apache.org/confluence/display/OFBIZ/The+infamous+Java+serialization+vulnerability
- https://issues.apache.org/jira/browse/OFBIZ-6726
- http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html
- http://www.securityfocus.com/archive/1/538033/100/0/threaded
- http://www.securitytracker.com/id/1035514
- https://issues.apache.org/jira/browse/OFBIZ-6506