CVE-2022-29063

CVE-2022-29063: Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz

Vendor Apache Software Foundation
Product Apache OFBiz
Weakness CWE-502 · Unsafe deserialization
Published September 2, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

Description

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12646.

Key dates

Disclosure timeline

September 2, 2022 CVE published
August 3, 2024 Record updated