
CVE-2021-37608 – Arbitrary file upload vulnerability in OFBiz
https://notcve.org/view.php?id=CVE-2021-37608
18 Aug 2021 — Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297. Una vulnerabilidad de Carga sin Restricciones de Archivos de Tipo Peligroso en Apache OFBiz, permite a un atacante ejecutar comandos remotos. Este problema afecta a Apache OFBiz versión 17.12.07 y versiones anteriores.... • https://lists.apache.org/thread.html/r164c91c47d638869c38e41b3ce501ecaa71f385939f098b2e04df049%40%3Cnotifications.ofbiz.apache.org%3E • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2021-30128 – Unsafe deserialization in Apache OFBiz
https://notcve.org/view.php?id=CVE-2021-30128
27 Apr 2021 — Apache OFBiz has unsafe deserialization prior to 17.12.07 version Apache OFBiz, presenta una deserialización no segura, anterior a versión 17.12.07 • https://github.com/LioTree/CVE-2021-30128-EXP • CWE-502: Deserialization of Untrusted Data •

CVE-2021-29200 – RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
https://notcve.org/view.php?id=CVE-2021-29200
27 Apr 2021 — Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack Apache OFBiz, presenta deserialización no segura anteriores a versión 17.12.07. Un usuario no autenticado puede llevar a cabo un ataque RCE • https://github.com/freeide/CVE-2021-29200 • CWE-502: Deserialization of Untrusted Data •

CVE-2021-26295 – RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
https://notcve.org/view.php?id=CVE-2021-26295
22 Mar 2021 — Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz. Apache OFBiz, presenta una deserialización no segura versiones anteriores a 17.12.06. Un atacante no autenticado puede usar esta vulnerabilidad para apoderarse con éxito de Apache OFBiz • https://packetstorm.news/files/id/162104 • CWE-502: Deserialization of Untrusted Data •

CVE-2020-9496 – ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
https://notcve.org/view.php?id=CVE-2020-9496
15 Jul 2020 — XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 La petición de XML-RPC es vulnerable a problemas de deserialización no segura y Cross-Site Scripting en Apache OFBiz versión 17.12.03 • https://packetstorm.news/files/id/163730 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-502: Deserialization of Untrusted Data •

CVE-2020-13923
https://notcve.org/view.php?id=CVE-2020-13923
15 Jul 2020 — IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 Vulnerabilidad de IDOR en la funcionalidad order processing del componente ecommerce de Apache OFBiz versiones anteriores a 17.12.04 • https://lists.apache.org/thread.html/r0a0a701610b3bcdf14634047313adab3f1628bb9aa55cf29cd262ef5%40%3Ccommits.ofbiz.apache.org%3E • CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2019-0235 – Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
https://notcve.org/view.php?id=CVE-2019-0235
30 Apr 2020 — Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. Apache OFBiz versión 17.12.01, es vulnerable a algunos ataques de tipo CSRF. Apache OFBiz version 17.12.03 suffers from a cross site request forgery vulnerability. • https://packetstorm.news/files/id/157514 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2019-12425
https://notcve.org/view.php?id=CVE-2019-12425
30 Apr 2020 — Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host Apache OFBiz versión 17.12.01, es vulnerable a una inyección del encabezado Host al aceptar host arbitrarios. • https://lists.apache.org/thread.html/r0a0a701610b3bcdf14634047313adab3f1628bb9aa55cf29cd262ef5%40%3Ccommits.ofbiz.apache.org%3E • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2020-1943
https://notcve.org/view.php?id=CVE-2020-1943
01 Apr 2020 — Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. Los datos enviados con contentId hacia /control/stream no son saneados, permitiendo ataques de tipo XSS en Apache OFBiz versiones 16.11.01 hasta 16.11.07. • https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc%40%3Ccommits.ofbiz.apache.org%3E • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-12426
https://notcve.org/view.php?id=CVE-2019-12426
06 Feb 2020 — an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06 Un usuario no autenticado podría obtener acceso a la información de algunas pantallas del back-end invocando setSessionLocale en Apache OFBiz versiones 16.11.01 hasta 16.11.06 • https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc%40%3Ccommits.ofbiz.apache.org%3E •