CVE-2022-47501
Apache OFBiz: Arbitrary file reading vulnerability
Record summary
CVE-2022-47501 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 7, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | VulnCheck, CVE List | Before 18.12.07 | affected |
Apache OFBizBrowse Apache Software Foundation / Apache OFBizDefault status: affected | CVE List | 18.12.06 to < 18.12.07 | affected |
Nuclei templates
1ProjectDiscoveryHIGHApache OFBiz < 18.12.07 - Local File InclusionCVSS 7.5
Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
Impact
Unauthenticated attackers can read arbitrary files from the server filesystem through the Solr plugin debug endpoint in Apache OFBiz, potentially accessing configuration files, credentials, and other sensitive system information.
Remediation
Upgrade to Apache OFBiz version 18.12.07 or later to mitigate this local file inclusion vulnerability.
Source: ProjectDiscovery