CVE-2022-47501: Apache OFBiz: Arbitrary file reading vulnerability
Published Apr 14, 2023
·Updated
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
Affected Software
1 affected component
Apache OFBiz<18.12.07
Remediation
Information
Upgrade to release 18.12.07
Event History
Apr 14, 2023
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-47501?
CVE-2022-47501 is an arbitrary file reading vulnerability in Apache OFBiz when using the Solr plugin.
2
What is the severity of CVE-2022-47501?
The severity of CVE-2022-47501 is high with a CVSS score of 7.5.
3
How does CVE-2022-47501 affect Apache OFBiz?
CVE-2022-47501 affects Apache OFBiz versions before 18.12.07.
4
Is CVE-2022-47501 a pre-authentication attack?
Yes, CVE-2022-47501 is a pre-authentication attack.
5
How do I fix CVE-2022-47501?
To fix CVE-2022-47501, upgrade Apache OFBiz to version 18.12.07 or later.