¡¾·ì϶¹«¸æ¡¿Apache OFBizÄ£°åÒýÇæ×¢Èë·ì϶(CVE-2025-26865)
°ä²¼¹¦·ò 2025-03-11Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Apache OFBizÄ£°åÒýÇæ×¢Èë·ì϶ | ||
CVE ID | CVE-2025-26865 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-11 |
·ì϶ÆÀ·Ö | 9.1 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache OFBizÊÇÒ»¸ö¿ªÔ´µÄÆóÒµ×ÊÔ´¹æ»®£¨ERP£©¿ò¼Ü£¬ÌṩÁËÒ»ÌׯëÈ«µÄÒµÎñÀûÓýâ¾ö¹æ»®¡£ËüÔ̺¬¶©µ¥ÖÎÀí¡¢¿â´æÖÎÀí¡¢¹ÜÕÊ¡¢¿Í»§¹ØÏµÖÎÀíµÈÄ£¿é£¬Ö§³Ö¸ß¶È¶¨Ô컯¡£OFBiz»ùÓÚJava¿ª·¢£¬ÓµÓÐ׳´óµÄÀ©´óÐԺͽýÝÐÔ£¬ºÏÓÃÓÚ¸÷ÀàÖÐÓ×ÐÍÆóÒµµÄÒµÎñÁ÷³ÌÖÎÀí¡£
2025Äê3ÔÂ11ÈÕ£¬GA»Æ½ð¼×VSRC¼à²âµ½Apache OFBiz°ä²¼Á˹ØÓÚCVE-2025-26865µÄ°²È«²¼¸æ¡£²¼¸æÖ¸³ö£¬Apache OFBizÄ£°åÒýÇæ´æÔÚ×¢Èë·ì϶£¬¿ÉÄܱ»¹¥»÷ÕßÀûÓÃÖ´ÐжñÒâ²Ù×÷£¬¸Ã·ì϶CVSSv3ÆÀ·Ö9.1£¬·ì϶µÈ¼¶ÎªÑϳÁ¡£
¶þ¡¢Ó°ÏìÁìÓò
18.12.17 < Apache OFBiz < 18.12.18
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÔÚApache OFBiz 18.12.18°æ±¾Öн¨¸´ÁËÄ£°åÒýÇæ×¢Èë·ì϶¡£Óû§Ó¦¾¡¿ìÉý¼¶ÖÁ18.12.18¼°Ö®ºó°æ±¾£¬ÒÔÈ·±£ÏµÍ³°²È«¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ