Back to Database
Status published
Medium
CVE-2019-12426
an unauthenticated user could get access to information of some...
Vulnerability Description
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-12426
Credits & Attribution
No credits recorded in the NVD database.
References
- https://s.apache.org/w0dem
- https://lists.apache.org/thread.html/r40a3c0930f7945e97e30c25422f52dbe476d5584346c3de5c556c272%40%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rf8651e75162819a267384f8a31c20884bc3a9a6707afbf75200cd98d%40%3Ccommits.ofbiz.apache.org%3E
- https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc%40%3Ccommits.ofbiz.apache.org%3E
More from Apache
View All →CVE-2024-42362
GHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/import
High
8.8
CVE-2024-42361
GHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metric/{metricFull}
High
7.5
CVE-2021-32824
Regular expression Denial of Service in MooTools
Critical
9.8
CVE-2020-9488
Improper validation of certificate with host mismatch in Apache Log4j...
Unknown
0
CVE-2020-9482
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism...
Medium
6.5
Affected Vendor
Apache
View all reports →Affected Software
Apache OFBiz
Vulnerable Versions:
Apache OFBiz 16.11.01 to 16.11.06
Timeline
Official Publish:
February 6th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.