RULE(RULE ID:338112)

Rule General Information
Release Date: 2024-06-07
Rule Name: Apache OFBiz Directory Traversal Vulnerability (CVE-2024-36104)
Severity:
CVE ID:
Rule Protection Details
Description: Improper Limitation of a Pathname to a Path Traversal vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14.Users are recommended to upgrade to version 18.12.14, which fixes the issue.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: https://issues.apache.org/jira/browse/OFBIZ-13092
https://lists.apache.org/thread/sv0xr8b1j7mmh5p37yldy9vmnzbodz2o
https://ofbiz.apache.org/download.html
https://ofbiz.apache.org/security.html
Solutions
Refer to the announcement or patch by the vendor: https://lists.apache.org/thread/sv0xr8b1j7mmh5p37yldy9vmnzbodz2o