CVE-2019-0189
 
Summary
Descriptions
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16
Es conocido que java.io.ObjectInputStream causa problemas de serialización del Java. Este problema aquí está expuesto por la URL "webtools/control/httpService" y usa la deserialización de Java para llevar a cabo la ejecución del código. En HttpEngine, el valor del parámetro request "serviceContext" es pasado al método "deserialize" de "XmlSerializer". Apache Ofbiz está afectado por dos dependencias diferentes: "commons-beanutils" y una versión obsoleta de "commons-fileupload", Mitigación: Actualice a la versión 16.11.06 o aplique manualmente las confirmaciones de OFBIZ-10770 y OFBIZ-10837 en la derivación 16
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-14 CVE Reserved
- 2019-09-11 CVE Published
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
Threat Intelligence Resources (0)
Select | Title | Date |
---|
Select an advisory to view details here.
Select | Title | Date |
---|
Select an exploit to view details here.
References (13)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://s.apache.org/hsn2g | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | >= 16.11.01 < 16.11.06 Search vendor "Apache" for product "Ofbiz" and version " >= 16.11.01 < 16.11.06" | - |
Affected
|