Insufficient verification of data authenticity in OFBiz - CVE-2022-29063

 

Insufficient verification of data authenticity in OFBiz - CVE-2022-29063

Published: April 10, 2023


Vulnerability identifier: #VU74611
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29063
CWE-ID: CWE-345
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to missing verification of data authenticity within the Solr plugin when processing RMI requests sent to localhost to port 1099. A local user with access to the system can host a malicious RMI server on the system and execute arbitrary code with privileges of Apache OFBiz during server start-up or on a server restart.


Affected software

OFBiz

How to mitigate CVE-2022-29063

Install updates from vendor's website.

OFBiz - update to 18.12.06

External References

Related Security Bulletins