CVE-2016-4462: Input Validation
Published Aug 30, 2017
·Updated
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
Affected Software
18 affected components
Apache OFBiz=11.04
Apache OFBiz=11.04.01
Apache OFBiz=11.04.02
Apache OFBiz=11.04.03
Apache OFBiz=11.04.04
Apache OFBiz=11.04.05
Apache OFBiz=11.04.06
Apache OFBiz=12.04
Apache OFBiz=12.04.01
Apache OFBiz=12.04.02
Apache OFBiz=12.04.03
Apache OFBiz=12.04.04
Apache OFBiz=12.04.05
Apache OFBiz=12.04.06
Apache OFBiz=13.07
Apache OFBiz=13.07.01
Apache OFBiz=13.07.02
Apache OFBiz=13.07.03
Event History
Aug 30, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-4462?
CVE-2016-4462 has a high severity rating due to the potential for remote code execution through crafted Freemarker templates.
2
How do I fix CVE-2016-4462?
To mitigate CVE-2016-4462, upgrade to Apache OFBiz version 16.11 or later.
3
Which versions of Apache OFBiz are affected by CVE-2016-4462?
CVE-2016-4462 affects Apache OFBiz versions 11.04 to 13.07.03.
4
Can CVE-2016-4462 be exploited without user authentication?
No, CVE-2016-4462 requires an authorized user to exploit the vulnerability.
5
What are the potential impacts of CVE-2016-4462?
The potential impacts of CVE-2016-4462 include remote code execution which could compromise system integrity.