5.3
CVSSv3

CVE-2019-12426

Published: 06/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache ofbiz

Mailing Lists

Severity: Minor Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 161101 to 161106 Description: an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale Mitigation: Upgrade to 161107 Credit: This issue was discovered by Dennis Balkir <dennisbalkir () ecomify ...