← Back

CVE-2016-4462

nvd nist
Published: Aug 30, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01

Affected (18)

Products: Apache: Ofbiz
1 product
Ofbiz
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 11.04.01
Version 11.04.02
Version 11.04.03
Version 11.04.04
Version 11.04.05
Version 11.04.06
Version 11.04
Version 12.04.01
Version 12.04.02
Version 12.04.03
Version 12.04.04
Version 12.04.05
Version 12.04.06
Version 12.04
Version 13.07.01
Version 13.07.02
Version 13.07.03
Version 13.07

References (2)

Source: security@apache.org
Third Party AdvisoryURL Repurposed
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryURL Repurposed

Timeline

No history available yet.