← Back to CVE List
Vulnerability Intelligence Report
Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz

CVE-2022-29063

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:3.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-502 ↗CWE-502 Deserialization of Untrusted Data

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache OFBiz Apache OFBiz <= 18.12.05 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.507%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2022-04-11T00:00:00
Published2022-09-02T07:10:19
Last Updated2024-08-03T06:10:59

LINK COPIED TO CLIPBOARD