← Volver a CVEs
CVE-2025-54466
CRITICAL9.8
Descripcion
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommended to upgrade to version 24.09.02, which fixes the issue.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado8/15/2025
Ultima modificacion11/4/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
apache:ofbiz
Debilidades (CWE)
CWE-94
Referencias
https://issues.apache.org/jira/browse/OFBIZ-13276(security@apache.org)
https://lists.apache.org/thread/14d0yd9co9gx2mctd3vyz1cc8d39n915(security@apache.org)
https://ofbiz.apache.org/download.html(security@apache.org)
https://ofbiz.apache.org/release-notes-24.09.02.html(security@apache.org)
https://ofbiz.apache.org/security.html(security@apache.org)
http://www.openwall.com/lists/oss-security/2025/08/05/1(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.