Insufficient verification of data authenticity in OFBiz - CVE-2022-29063
Published: April 10, 2023
OFBiz
Apache Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to missing verification of data authenticity within the Solr plugin when processing RMI requests sent to localhost to port 1099. A local user with access to the system can host a malicious RMI server on the system and execute arbitrary code with privileges of Apache OFBiz during server start-up or on a server restart.