Insufficient verification of data authenticity in OFBiz - CVE-2022-29063

 

Insufficient verification of data authenticity in OFBiz - CVE-2022-29063

Published: April 10, 2023


Vulnerability identifier: #VU74611
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-29063
CWE-ID: CWE-345
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
OFBiz
Software vendor:
Apache Foundation

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to missing verification of data authenticity within the Solr plugin when processing RMI requests sent to localhost to port 1099. A local user with access to the system can host a malicious RMI server on the system and execute arbitrary code with privileges of Apache OFBiz during server start-up or on a server restart.


Remediation

Install updates from vendor's website.

External links