CVE-2019-12426

MEDIUM

Apache OFBiz <16.11.07 - Info Disclosure

Title source: llm
STIX 2.1

Description

an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06

Scores

CVSS v3 5.3
EPSS 0.0120
EPSS Percentile 79.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
apache/ofbiz 16.11.01 - 16.11.06
Published Feb 06, 2020
Tracked Since Feb 18, 2026