CVE-2020-9496
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (2)
NVD, NVD
CWE (2)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-502: Deserialization of Untrusted Data
CAPEC (-)
Risk
CVSS Score
6.1 Medium
SSVC
-
KEV
-
EPSS
92.3%
Affected Products (-)
Vendors (1)
apache
Products (1)
ofbiz
Versions (1)
17.12.03
Intel Resources (4)
Advisories (-)
-
Exploits (4)
PacketStorm, rapid7
Plugins (-)
-
References (27)
General (10)
apache, github, sonicwall
Exploits & POcs (16)
packetstorm, exploit-db, github ...
Patches (-)
Advisories (1)
apache
Summary
Descriptions
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
La petición de XML-RPC es vulnerable a problemas de deserialización no segura y Cross-Site Scripting en Apache OFBiz versión 17.12.03
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-03-01 CVE Reserved
- 2020-07-15 CVE Published
- 2020-08-16 First Exploit
- 2024-08-04 CVE Updated
- 2024-12-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-502: Deserialization of Untrusted Data
CAPEC
Threat Intelligence Resources (4)
Select | Title | Date |
---|
Security Advisory details:
Select an advisory to view details here.
Select | Title | Date |
---|---|---|
Apache OfBiz 17.12.01 Remote Command Execution | 2021-08-04 | |
Apache OFBiz XML-RPC Java Deserialization | 2021-03-12 | |
Apache OFBiz XML-RPC Java Deserialization | 2020-08-17 | |
Apache OFBiz XML-RPC Java Deserialization | 2020-07-13 |
Select an exploit to view details here.
References (27)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://s.apache.org/l0994 | 2023-11-07 |