Record summary

CVE-2022-47501 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

VulnCheck, CVE ListBefore 18.12.07affected

Default status: affected

CVE List18.12.06 to < 18.12.07affected

Nuclei templates

1
ProjectDiscoveryHIGHApache OFBiz < 18.12.07 - Local File InclusionCVSS 7.5

Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.

Impact

Unauthenticated attackers can read arbitrary files from the server filesystem through the Solr plugin debug endpoint in Apache OFBiz, potentially accessing configuration files, credentials, and other sensitive system information.

Remediation

Upgrade to Apache OFBiz version 18.12.07 or later to mitigate this local file inclusion vulnerability.

WeaknessesCWE-22
Authorsyour3cho
Template tagscvecve2022apacheofbizlfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Shodan: html:"OFBiz"
Shodan: http.html:"ofbiz"
Shodan: ofbiz.visitor=
FOFA: app="Apache_OFBiz"
FOFA: body="ofbiz"
FOFA: app="apache_ofbiz"

Source: ProjectDiscovery

References

8