¡¾·ì϶¹«¸æ¡¿Apache OFBizÄ£°åÒýÇæ×¢Èë·ì϶(CVE-2025-26865)
°ä²¼¹¦·ò 2025-03-11Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Apache OFBizÄ£°åÒýÇæ×¢Èë·ì϶ | ||
CVE ID | CVE-2025-26865 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-03-11 |
·ì϶ÆÀ·Ö | 9.1 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache OFBizÊÇÒ»¸ö¿ªÔ´µÄÆóÒµ×ÊÔ´¹æ»®£¨ERP£©¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬ÌṩÁËÒ»ÌׯëÈ«µÄÒµÎñÀûÓýâ¾ö¹æ»®¡£¡£¡£¡£¡£¡£ËüÔ̺¬¶©µ¥ÖÎÀí¡¢¿â´æÖÎÀí¡¢¹ÜÕÊ¡¢¿Í»§¹ØÏµÖÎÀíµÈÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¸ß¶È¶¨Ô컯¡£¡£¡£¡£¡£¡£OFBiz»ùÓÚJava¿ª·¢£¬£¬£¬£¬£¬£¬£¬ÓµÓÐ׳´óµÄÀ©´óÐԺͽýÝÐÔ£¬£¬£¬£¬£¬£¬£¬ºÏÓÃÓÚ¸÷ÀàÖÐÓ×ÐÍÆóÒµµÄÒµÎñÁ÷³ÌÖÎÀí¡£¡£¡£¡£¡£¡£
2025Äê3ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅVSRC¼à²âµ½Apache OFBiz°ä²¼Á˹ØÓÚCVE-2025-26865µÄ°²È«²¼¸æ¡£¡£¡£¡£¡£¡£²¼¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬Apache OFBizÄ£°åÒýÇæ´æÔÚ×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ»¹¥»÷ÕßÀûÓÃÖ´ÐжñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶CVSSv3ÆÀ·Ö9.1£¬£¬£¬£¬£¬£¬£¬·ì϶µÈ¼¶ÎªÑϳÁ¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
18.12.17 < Apache OFBiz < 18.12.18
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÔÚApache OFBiz 18.12.18°æ±¾Öн¨¸´ÁËÄ£°åÒýÇæ×¢Èë·ì϶¡£¡£¡£¡£¡£¡£Óû§Ó¦¾¡¿ìÉý¼¶ÖÁ18.12.18¼°Ö®ºó°æ±¾£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£ÏµÍ³°²È«¡£¡£¡£¡£¡£¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ