Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-12426

an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 86.0%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
References
Products affected by CVE-2019-12426
  • Apache » Ofbiz » Version: 16.11.01
    cpe:2.3:a:apache:ofbiz:16.11.01
  • Apache » Ofbiz » Version: 16.11.02
    cpe:2.3:a:apache:ofbiz:16.11.02
  • Apache » Ofbiz » Version: 16.11.03
    cpe:2.3:a:apache:ofbiz:16.11.03
  • Apache » Ofbiz » Version: 16.11.04
    cpe:2.3:a:apache:ofbiz:16.11.04
  • Apache » Ofbiz » Version: 16.11.05
    cpe:2.3:a:apache:ofbiz:16.11.05
  • Apache » Ofbiz » Version: 16.11.06
    cpe:2.3:a:apache:ofbiz:16.11.06


Contact Us

Shodan ® - All rights reserved