HTTP: Apache OFBiz 18.12.11 Server Side Request Forgery

This signature detects attempts to exploit a known vulnerability against Apache Ofbiz. A successful attack can lead to sensitive information disclosure.

Extended Description

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

Affected Products

Apache ofbiz

References

CVE: CVE-2023-50968

Short Name
HTTP:APACHE-OFBIZ-SSRF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
18.12.11 Apache CVE-2023-50968 Forgery OFBiz Request Server Side
Release Date
02/08/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3676
False Positive
Unknown
Vendors

Apache

Found a potential security threat?