Vulnerability Details CVE-2022-29063
The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.121
EPSS Ranking 93.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-29063
-
-
cpe:2.3:a:apache:ofbiz:09.04
-
cpe:2.3:a:apache:ofbiz:09.04.01
-
cpe:2.3:a:apache:ofbiz:10.04
-
cpe:2.3:a:apache:ofbiz:10.04.01
-
cpe:2.3:a:apache:ofbiz:10.04.02
-
cpe:2.3:a:apache:ofbiz:10.04.03
-
cpe:2.3:a:apache:ofbiz:10.04.04
-
cpe:2.3:a:apache:ofbiz:10.04.05
-
cpe:2.3:a:apache:ofbiz:10.04.06
-
cpe:2.3:a:apache:ofbiz:11.04
-
cpe:2.3:a:apache:ofbiz:11.04.01
-
cpe:2.3:a:apache:ofbiz:11.04.02
-
cpe:2.3:a:apache:ofbiz:11.04.03
-
cpe:2.3:a:apache:ofbiz:11.04.04
-
cpe:2.3:a:apache:ofbiz:11.04.05
-
cpe:2.3:a:apache:ofbiz:11.04.06
-
cpe:2.3:a:apache:ofbiz:12.04
-
cpe:2.3:a:apache:ofbiz:12.04.01
-
cpe:2.3:a:apache:ofbiz:12.04.02
-
cpe:2.3:a:apache:ofbiz:12.04.03
-
cpe:2.3:a:apache:ofbiz:12.04.04
-
cpe:2.3:a:apache:ofbiz:12.04.05
-
cpe:2.3:a:apache:ofbiz:12.04.06
-
cpe:2.3:a:apache:ofbiz:13.07
-
cpe:2.3:a:apache:ofbiz:13.07.01
-
cpe:2.3:a:apache:ofbiz:13.07.02
-
cpe:2.3:a:apache:ofbiz:13.07.03
-
cpe:2.3:a:apache:ofbiz:16.11.01
-
cpe:2.3:a:apache:ofbiz:16.11.02
-
cpe:2.3:a:apache:ofbiz:16.11.03
-
cpe:2.3:a:apache:ofbiz:16.11.04
-
cpe:2.3:a:apache:ofbiz:16.11.05
-
cpe:2.3:a:apache:ofbiz:16.11.06
-
cpe:2.3:a:apache:ofbiz:16.11.07
-
cpe:2.3:a:apache:ofbiz:17.12.01
-
cpe:2.3:a:apache:ofbiz:17.12.03
-
cpe:2.3:a:apache:ofbiz:17.12.04
-
cpe:2.3:a:apache:ofbiz:17.12.05
-
cpe:2.3:a:apache:ofbiz:17.12.06
-
cpe:2.3:a:apache:ofbiz:17.12.07
-
cpe:2.3:a:apache:ofbiz:17.12.08
-
cpe:2.3:a:apache:ofbiz:17.12.09
-
cpe:2.3:a:apache:ofbiz:18.12.01
-
cpe:2.3:a:apache:ofbiz:18.12.02
-
cpe:2.3:a:apache:ofbiz:18.12.03
-
cpe:2.3:a:apache:ofbiz:18.12.04
-
cpe:2.3:a:apache:ofbiz:18.12.05
-
cpe:2.3:a:apache:ofbiz:9.04
-
cpe:2.3:a:apache:ofbiz:9.04.01
-
cpe:2.3:a:apache:ofbiz:9.04.02