首页
学习
活动
专区
圈层
工具
发布
社区首页 >专栏 >CVE-2025-59118:Apache OFBiz 严重反序列化漏洞深度剖析

CVE-2025-59118:Apache OFBiz 严重反序列化漏洞深度剖析

原创
作者头像
qife122
发布2026-02-16 11:31:24
发布2026-02-16 11:31:24
910
举报

🚨 CVE-2025-59118: Critical Apache OFBiz RCE 🚨

Unrestricted File Upload = Full Server Compromise 💥

------------|-----------|

| CVE ID | CVE-2025-59118 🔖 |

| Title | Unrestricted Upload of File with Dangerous Type 📂⚠️ |

| Severity | Critical 🔥 (CVSS ~9.0+ expected) |

| CWE | CWE-434 🛡️ |

| Affected | Apache OFBiz < 24.09.03 ❌ |

| Fixed In | 24.09.03+ ✅ |

| Published | Nov 12, 2025 📅 |

| Attack Type | Remote Code Execution (RCE) 💻💣 |

| Auth Required? | Yes (low-privilege user) 🔑 |

Impact

Risk

Level

Server Takeover

🌕🌕🌕🌕🌕

Data Theft

💳📊

Ransomware

🔒💰

Lateral Movement

🌐➡️🏢

ERP systems = high-value targets 🏦

🔗 Official References

--------|------------|----------|

| ZoomEye | 844 | app="Apache OFBiz" |

| Hunter | 1,200+ | product.name="OFBiz" |

| FOFA | 1,600+ | app="Apache_OFBiz" |

Patch now. Scan now. Sleep later. 😴

-----|--------|--------|

| @zoomeye_team | "🚨 CVE-2025-59118 + XSS → 844 exposed OFBiz hosts!" | Nov 13 |

| @HunterMapping | "1.2K+ live targets. Patch or perish." | Nov 13 |

| @fofabot | "1.6K results on FOFA. RCE via upload." | Nov 12 |

| @CVEnew | "Official: Upgrade to 24.09.03" | Nov 12 |

Final Verdict

"If you're running OFBiz < 24.09.03, you're one upload away from a breach."

Act now. Patch fast. Stay safe. 🔐✨FINISHED

6HFtX5dABrKlqXeO5PUv/84SoIo+TE3firf/5vX8AZ7VRvjVaY53XtS2qtHP029N

原创声明:本文系作者授权腾讯云开发者社区发表,未经许可,不得转载。

如有侵权,请联系 cloudcommunity@tencent.com 删除。

原创声明:本文系作者授权腾讯云开发者社区发表,未经许可,不得转载。

如有侵权,请联系 cloudcommunity@tencent.com 删除。

评论
登录后参与评论
0 条评论
热度
最新
推荐阅读
目录
  • 🚨 CVE-2025-59118: Critical Apache OFBiz RCE 🚨
    • ⚡ Impact
    • 🔗 Official References
    • ✅ Final Verdict
领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档