Rewterz Threat Advisory – CVE-2020-15648 – Mozilla Thunderbird X-Frame-Options header security bypass
July 17, 2020Rewterz Threat Alert – The Tetrade: Brazilian Banking Malware Goes Global
July 17, 2020Rewterz Threat Advisory – CVE-2020-15648 – Mozilla Thunderbird X-Frame-Options header security bypass
July 17, 2020Rewterz Threat Alert – The Tetrade: Brazilian Banking Malware Goes Global
July 17, 2020Severity
Medium
Analysis Summary
CVE-2020-13923
Apache OFBiz could allow a remote attacker to bypass security restrictions, caused by an IDOR vulnerability in the order processing feature from ecommerce component. An attacker could exploit this vulnerability to bypass access restrictions to access objects directly.
CVE-2020-9496
Apache OFBiz is vulnerable to cross-site scripting, caused by the manipulation as part of a XML-RPC Request. A remote attacker could exploit this vulnerability using XML-RPC request to execute script in a victim’s Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Impact
- Security bypass
- Cross-site scripting
Affected Vendors
Apache
Affected Products
Apache OFBiz 17.12.03
Remediation
Upgrade to the latest version of OFBiz (17.12.04 or later).