CVE Database
/

CVE-2021-25958

Back to search

CVE-2021-25958

Published: Aug 30, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.

VendorProductVersions

apache

ofbiz-framework

affected
v17.12.01 - < unspecified
affected
unspecified - <= v17.12.07

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now