CVE-2016-4462
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
30/08/2017
Last modified:
20/04/2025
Description
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:ofbiz:11.04:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:11.04.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:11.04.02:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:11.04.03:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:11.04.04:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:11.04.05:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:11.04.06:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:12.04:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:12.04.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:12.04.02:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:12.04.03:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:12.04.04:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:12.04.05:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:12.04.06:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:ofbiz:13.07:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



