CVE-2021-25958 - CVE House
Back to Database
Status published Medium CVE-2021-25958

Generation of Error Message Containing Sensitive Information in Apache OFBiz

Vulnerability Description

In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25958

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ofbiz-framework
Vulnerable Versions:
v17.12.01, unspecified

Timeline

Official Publish: August 30th, 2021
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Weaknesses (CWE)