¡¾·ì϶¹«¸æ¡¿Apache OFBizÄ£°åÒýÇæ×¢Èë·ì϶(CVE-2025-26865)
°ä²¼¹¦·ò 2025-03-11Ò»¡¢¡¢¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Apache OFBizÄ£°åÒýÇæ×¢Èë·ì϶ | ||
CVE ID | CVE-2025-26865 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-11 |
·ì϶ÆÀ·Ö | 9.1 | ·ì϶µÈ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache OFBizÊÇÒ»¸ö¿ªÔ´µÄÆóÒµ×ÊÔ´¹æ»®£¨ERP£©¿ò¼Ü£¬£¬ÌṩÁËÒ»ÌׯëÈ«µÄÒµÎñÀûÓýâ¾ö¹æ»®¡£¡£ËüÔ̺¬¶©µ¥ÖÎÀí¡¢¡¢¡¢¿â´æÖÎÀí¡¢¡¢¡¢¹ÜÕÊ¡¢¡¢¡¢¿Í»§¹ØÏµÖÎÀíµÈÄ£¿£¿£¿é£¬£¬Ö§³Ö¸ß¶È¶¨ÖÆ»¯¡£¡£OFBiz»ùÓÚJava¿ª·¢£¬£¬ÓµÓÐ׳´óµÄÀ©´óÐԺͽýÝÐÔ£¬£¬ºÏÓÃÓÚ¸÷ÀàÖÐСÐÍÆóÒµµÄÒµÎñÁ÷³ÌÖÎÀí¡£¡£
2025Äê3ÔÂ11ÈÕ£¬£¬OG¶«·½ÌüVSRC¼à²âµ½Apache OFBiz°ä²¼Á˹ØÓÚCVE-2025-26865µÄ°²È«²¼¸æ¡£¡£²¼¸æÖ¸³ö£¬£¬Apache OFBizÄ£°åÒýÇæ´æÔÚ×¢Èë·ì϶£¬£¬¿ÉÄܱ»¹¥»÷ÕßÀûÓÃÖ´ÐжñÒâ²Ù×÷£¬£¬¸Ã·ì϶CVSSv3ÆÀ·Ö9.1£¬£¬·ì϶µÈ¼¶ÎªÑÏÖØ¡£¡£
¶þ¡¢¡¢¡¢Ó°ÏìÁìÓò
18.12.17 < Apache OFBiz < 18.12.18
Èý¡¢¡¢¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÔÚApache OFBiz 18.12.18°æ±¾ÖÐÐÞ¸´ÁËÄ£°åÒýÇæ×¢Èë·ì϶¡£¡£Óû§Ó¦¾¡¿ìÉý¼¶ÖÁ18.12.18¼°Ö®ºó°æ±¾£¬£¬ÒÔÈ·±£ÏµÍ³°²È«¡£¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ