← volver
CVE-2022-25371CWE-22

Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz

3Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 5.1%
probabilidad de explotación
5.1%top 8% de las CVE
explotación observada
noninguna fuente lo reporta
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.