¡¾Îó²îͨ¸æ¡¿Apache OFBizÄ£°åÒýÇæ×¢ÈëÎó²î(CVE-2025-26865)
Ðû²¼Ê±¼ä 2025-03-11Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache OFBizÄ£°åÒýÇæ×¢ÈëÎó²î | ||
CVE ID | CVE-2025-26865 | ||
Îó²îÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-03-11 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache OFBizÊÇÒ»¸ö¿ªÔ´µÄÆóÒµ×ÊÔ´ÍýÏ루ERP£©¿ò¼Ü£¬£¬£¬£¬ÌṩÁËÒ»Ì×ÍêÕûµÄÓªÒµÓ¦Óýâ¾ö¼Æ»®¡£¡£¡£Ëü°üÀ¨¶©µ¥ÖÎÀí¡¢¿â´æÖÎÀí¡¢»á¼Æ¡¢¿Í»§¹ØÏµÖÎÀíµÈÄ£¿£¿£¿é£¬£¬£¬£¬Ö§³Ö¸ß¶È¶¨ÖÆ»¯¡£¡£¡£OFBiz»ùÓÚJava¿ª·¢£¬£¬£¬£¬¾ßÓÐǿʢµÄÀ©Õ¹ÐÔºÍÎÞаÐÔ£¬£¬£¬£¬ÊÊÓÃÓÚÖÖÖÖÖÐСÐÍÆóÒµµÄÓªÒµÁ÷³ÌÖÎÀí¡£¡£¡£
2025Äê3ÔÂ11ÈÕ£¬£¬£¬£¬¼øºÚµ£±£ÍøVSRC¼à²âµ½Apache OFBizÐû²¼Á˹ØÓÚCVE-2025-26865µÄÇ徲ͨ¸æ¡£¡£¡£Í¨¸æÖ¸³ö£¬£¬£¬£¬Apache OFBizÄ£°åÒýÇæ±£´æ×¢ÈëÎó²î£¬£¬£¬£¬¿ÉÄܱ»¹¥»÷ÕßʹÓÃÖ´ÐжñÒâ²Ù×÷£¬£¬£¬£¬¸ÃÎó²îCVSSv3ÆÀ·Ö9.1£¬£¬£¬£¬Îó²îÆ·¼¶ÎªÑÏÖØ¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
18.12.17 < Apache OFBiz < 18.12.18
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÔÚApache OFBiz 18.12.18°æ±¾ÖÐÐÞ¸´ÁËÄ£°åÒýÇæ×¢ÈëÎó²î¡£¡£¡£Óû§Ó¦¾¡¿ìÉý¼¶ÖÁ18.12.18¼°Ö®ºó°æ±¾£¬£¬£¬£¬ÒÔÈ·±£ÏµÍ³Çå¾²¡£¡£¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£