Apache OFBiz - Unauth Stored XSS (CVE-2022-25370)

2022-09-01 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-01 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-01 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Java Deserialization via RMI Connection (CVE-2022-29063)

2022-09-01 Thread Jacques Le Roux
Severity: Low (only on shared servers) Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The OFBiz Solr plugin is configured by default to automatically make a RMI request on localhost, port 1099. By hosting a malicious RMI server on localho

Apache OFBiz - Regular Expression Denial of Service (ReDoS) [CVE-2022-29158]

2022-09-01 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Mitig

Subject: Apache OFBiz - Server-Side Template Injection (CVE-2022-25813)

2022-09-01 Thread Jacques Le Roux
Severity: High (SSTI then possible RCE) Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: As an ecommerce anonymous client, an external attacker can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a p

[ANNOUNCE] Apache OFBiz 18.12 End-Of-Life (EOL) announcement

2022-09-01 Thread Jacques Le Roux
The Apache OFBiz Project Team would like to inform you that OFBiz 18.12.06 is the last release of the 18.12 branch, which has reached its end of life and won't be longer officially supported. https://ofbiz.apache.org/release-notes-18.12.06.html This announcement takes place on 2022-09-02 and sta

Re: Questions regarding purchase orders

2022-09-01 Thread Rishi Solanki
Dear Emad, If you notice then Shipment is Purchase Shipment and Item Issuance is link with inventory item. Shipment will be incoming shipment and with item issuance inventory received against that order. Rishi Solanki *CTO, Mindpath Technology* Intelligent Solutions cell: +91-98932-87847 LinkedIn

Re: Mappings for invoice items and order items

2022-09-01 Thread Ashish Vijaywargiya
Acknowledged. -- Kind Regards, Ashish Vijaywargiya Vice President of Operations *HotWax Systems* *Enterprise open source experts* http://www.hotwaxsystems.com On Thu, Sep 1, 2022 at 4:31 PM Emad Radwan wrote: > Hello Ashish, > > Many many thanks that is really very helpful. > > May I be greed

Re: GL Account Balance

2022-09-01 Thread Ashish Vijaywargiya
Hello Emad, Please check the "AcctgTransEntrySums" view entity(It has all credit/debit entries based on the GlAccount). https://demo-stable.ofbiz.apache.org/webtools/control/FindGeneric?entityName=AcctgTransEntrySums Here is the definition of View Entity from accounting-entitymodel.xml:

[ANNOUNCE] Apache OFBiz 18.12.06 released

2022-09-01 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.06". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.06" is the sixt

Re: Mappings for invoice items and order items

2022-09-01 Thread Emad Radwan
Hello Ashish, Many many thanks that is really very helpful. May I be greedy and ask you kindly to look at another question from me recently regarding ‘GL Account Balance’ as no one answered it? Thanks again and best regards, Emad > On 1 Sep 2022, at 8:57 AM, Ashish Vijaywargiya > wrote: >