Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-1525 Issue to group security concerns
  3. OFBIZ-12646

Java Deserialization vulnerability in Apache OfBiz (CVE-2022-29063)

    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 18.12.06, 22.01.01
    • solr
    • None
    • Bug Crush Event - 21/2/2015

    Description

      The following vulnerability has been found by Matei "Mal" Badanoiu. It's a Java Deserialization via RMI Connection.

      The OfBiz Solr plugin is configured by default to automatically make a RMI request on localhost, port 1099.
      By hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code as the user that started OfBiz and potentially elevate his/her privileges.

      We (security team) want to Note that this exploit can only be done on a shared server. That's why it's of low severity.

      Attachments

        Activity

          People

            jleroux Jacques Le Roux
            jleroux Jacques Le Roux
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: