CVE-2019-12426: Medium severity apache ofbiz vulnerability
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12426?
CVE-2019-12426 is a vulnerability in Apache OFBiz 16.11.01 to 16.11.06 that allows an unauthenticated user to access information of some backend screens by invoking setSessionLocale.
What is the severity of CVE-2019-12426?
The severity of CVE-2019-12426 is medium with a CVSS score of 5.3.
How can an unauthenticated user exploit CVE-2019-12426?
An unauthenticated user can exploit CVE-2019-12426 by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06.
How can I prevent CVE-2019-12426?
To prevent CVE-2019-12426, you should update Apache OFBiz to a version higher than 16.11.06.
Where can I find more information about CVE-2019-12426?
You can find more information about CVE-2019-12426 at the following references: [Reference 1](https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc@%3Ccommits.ofbiz.apache.org%3E), [Reference 2](https://lists.apache.org/thread.html/r40a3c0930f7945e97e30c25422f52dbe476d5584346c3de5c556c272@%3Cannounce.apache.org%3E), [Reference 3](https://lists.apache.org/thread.html/rf8651e75162819a267384f8a31c20884bc3a9a6707afbf75200cd98d@%3Ccommits.ofbiz.apache.org%3E).