Rewterz
Rewterz Threat Advisory – CVE-2020-15648 – Mozilla Thunderbird X-Frame-Options header security bypass
July 17, 2020
Rewterz
Rewterz Threat Alert – The Tetrade: Brazilian Banking Malware Goes Global
July 17, 2020

Rewterz Threat Advisory – Apache OFBiz IDOR Multiple Security Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2020-13923

Apache OFBiz could allow a remote attacker to bypass security restrictions, caused by an IDOR vulnerability in the order processing feature from ecommerce component. An attacker could exploit this vulnerability to bypass access restrictions to access objects directly.

CVE-2020-9496

Apache OFBiz is vulnerable to cross-site scripting, caused by the manipulation as part of a XML-RPC Request. A remote attacker could exploit this vulnerability using XML-RPC request to execute script in a victim’s Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Impact

  • Security bypass
  • Cross-site scripting

Affected Vendors

Apache

Affected Products

Apache OFBiz 17.12.03

Remediation

Upgrade to the latest version of OFBiz (17.12.04 or later).