CVE-2019-12426
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache O
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06.
MEDIUM · CVSS 5.3
EPSS 0.012
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0