¡¾Îó²îͨ¸æ¡¿Apache OFBizÄ£°åÒýÇæ×¢ÈëÎó²î(CVE-2025-26865)
Ðû²¼Ê±¼ä 2025-03-11Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache OFBizÄ£°åÒýÇæ×¢ÈëÎó²î | ||
CVE ID | CVE-2025-26865 | ||
Îó²îÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-11 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache OFBizÊÇÒ»¸ö¿ªÔ´µÄÆóÒµ×ÊÔ´ÍýÏ루ERP£©¿ò¼Ü£¬ÌṩÁËÒ»Ì×ÍêÕûµÄÓªÒµÓ¦Óýâ¾ö¼Æ»®¡£Ëü°üÀ¨¶©µ¥ÖÎÀí¡¢¿â´æÖÎÀí¡¢»á¼Æ¡¢¿Í»§¹ØÏµÖÎÀíµÈÄ£¿é£¬Ö§³Ö¸ß¶È¶¨ÖÆ»¯¡£OFBiz»ùÓÚJava¿ª·¢£¬¾ßÓÐǿʢµÄÀ©Õ¹ÐÔºÍÎÞаÐÔ£¬ÊÊÓÃÓÚÖÖÖÖÖÐСÐÍÆóÒµµÄÓªÒµÁ÷³ÌÖÎÀí¡£
2025Äê3ÔÂ11ÈÕ£¬×ðÁú¿Ê±VSRC¼à²âµ½Apache OFBizÐû²¼Á˹ØÓÚCVE-2025-26865µÄÇ徲ͨ¸æ¡£Í¨¸æÖ¸³ö£¬Apache OFBizÄ£°åÒýÇæ±£´æ×¢ÈëÎó²î£¬¿ÉÄܱ»¹¥»÷ÕßʹÓÃÖ´ÐжñÒâ²Ù×÷£¬¸ÃÎó²îCVSSv3ÆÀ·Ö9.1£¬Îó²îÆ·¼¶ÎªÑÏÖØ¡£
¶þ¡¢Ó°Ïì¹æÄ£
18.12.17 < Apache OFBiz < 18.12.18
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÔÚApache OFBiz 18.12.18°æ±¾ÖÐÐÞ¸´ÁËÄ£°åÒýÇæ×¢ÈëÎó²î¡£Óû§Ó¦¾¡¿ìÉý¼¶ÖÁ18.12.18¼°Ö®ºó°æ±¾£¬ÒÔÈ·±£ÏµÍ³Çå¾²¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ