[CVE-2013-2250] Apache OFBiz Nested expression evaluation allows remote users to execute arbitrary UEL functions in OFBiz

2013-07-20 Thread Jacopo Cappellato
CVE-2013-2250 - Apache OFBiz Nested expression evaluation allows remote users to execute arbitrary UEL functions in OFBiz Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: Parameter

[ANNOUNCE] Apache OFBiz 12.04.02 released

2013-07-20 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 12.04.02. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 12.04.02 is a bug fix release for

[CVE-2013-2137] Apache OFBiz XSS vulnerability in the View Log screen of the Webtools application

2013-07-20 Thread Jacopo Cappellato
CVE-2013-2137 - Apache OFBiz XSS vulnerability in the View Log screen of the Webtools application Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: XSS vulnerability in the View Log

[ANNOUNCE] Apache OFBiz 11.04.03 released

2013-07-20 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 11.04.03. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 11.04.03 is a bug fix release for

[ANNOUNCE] Apache OFBiz 10.04.06 released

2013-07-20 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 10.04.06. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 10.04.06 is the last bug fix release