[ANNOUNCE] Apache OFBiz 18.12.14 released

2024-05-31 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.14". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.14" is the

[ANNOUNCE] Apache OFBiz 18.12.13 released

2024-05-07 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.13". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.13" is the

[ANNOUNCE] Apache OFBiz 18.12.12 released

2024-02-28 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.12". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.12" is the

[ANNOUNCE] Apache OFBiz 18.12.11 released

2023-12-22 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.11". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.11" is the

[ANNOUNCE] Apache OFBiz 18.12.10 released

2023-12-04 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.10". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.10" is the

[ANNOUNCE] Apache OFBiz 18.12.09 released

2023-11-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.09". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.09" is the

[ANNOUNCE] Apache OFBiz 18.12.08 released

2023-06-01 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.08". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.08" is the

[ANNOUNCE] Apache OFBiz 18.12.07 released

2023-04-10 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.07". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.07" is the

[ANNOUNCE] Apache OFBiz 18.12.06 released

2022-09-01 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.06". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.06" is the

[ANNOUNCE] Apache OFBiz 18.12.05 released

2022-01-04 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.05". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.05" is the

[ANNOUNCE] Apache OFBiz 18.12.04 released

2021-12-20 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.04". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.04" is the

[ANNOUNCE] Apache OFBiz 18.12.03 released

2021-12-13 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.03". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.03" is the

[ANNOUNCE] Apache OFBiz 18.12.02 released

2021-11-24 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.02". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.02" is the

[ANNOUNCE] Apache OFBiz 18.12.01 released

2021-10-29 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 18.12.01". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 18.12.01" is the

[ANNOUNCE] Apache OFBiz 17.12.08 released

2021-08-11 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.08". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.08" is the

[ANNOUNCE] Apache OFBiz 17.12.06 released

2021-03-21 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.06". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.06" is the

[ANNOUNCE] Apache OFBiz 17.12.05 released

2021-01-12 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.05". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.05" is the

[ANNOUNCE] Apache OFBiz 17.12.04 release

2020-07-15 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.04". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.04" is the

[ANNOUNCE] Apache OFBiz 17.12.03 release

2020-04-30 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.03". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.03" is the

[ANNOUNCE] Apache OFBiz 17.12.01 release

2020-03-06 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.01". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.01" is the

[CVE-2020-1943] Apache OFBiz XSS Vulnerability

2020-03-06 Thread Jacopo Cappellato
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.07 Description: Data sent with "contentId" to "/control/stream" is not sanitized, allowing XSS attacks. Mitigation: Upgrade to 17.12.01 or manually apply the commits at OFBIZ-10753

[SECURITY] CVE-2019-12426 information disclosure vulnerability in Apache OFBiz

2020-02-06 Thread Jacopo Cappellato
Severity: Minor Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 16.11.01 to 16.11.06 Description: an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale. Mitigation: Upgrade to 16.11.07 Credit: This issue was

[ANNOUNCE] Apache OFBiz 16.11.07 released

2020-02-06 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 16.11.07". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 16.11.07" is the

[CVE-2019-10074] Apache OFBiz RCE (template injection)

2019-09-11 Thread Jacopo Cappellato
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.05 An RCE is possible by entering Freemarker markup in an OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story"

[CVE-2019-10073] Apache OFBiz XSS vulnerability in the "ecommerce" component

2019-09-11 Thread Jacopo Cappellato
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.05 Description: The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or

[CVE-2019-0189] Apache OFBiz remote code execution and arbitrary file delete via Java deserialization

2019-09-11 Thread Jacopo Cappellato
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.05 Description: The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to

[CVE-2018-17200] Apache OFBiz unauthenticated remote code execution vulnerability in HttpEngine

2019-09-11 Thread Jacopo Cappellato
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.05 Description: The OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes

[ANNOUNCE] Apache OFBiz 16.11.06 released

2019-09-11 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 16.11.06". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 16.11.06" is the

[ANNOUNCE] Apache OFBiz 16.11.05 released

2018-10-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 16.11.05". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 16.11.05" is the

[ANNOUNCE] Apache OFBiz 16.11.04 released

2018-01-03 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 16.11.04". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 16.11.04" is the

[ANNOUNCE] Apache OFBiz 16.11.03 released

2017-07-03 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 16.11.03". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 16.11.03" is the

[ANNOUNCE] Apache OFBiz 16.11.02 released

2017-05-24 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 16.11.02". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 16.11.02" is the

[SECURITY] CVE-2016-4462 OFBiz template remote code vulnerability

2016-11-29 Thread Jacopo Cappellato
Vendor: The Apache Software Foundation Versions Affected: OFBiz 13.07.* OFBiz 12.04.* OFBiz 11.04.* Description: By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a

[ANNOUNCE] Apache OFBiz 16.11.01 released

2016-11-28 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 16.11.01". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 16.11.01" is the

[ANNOUNCE] Apache OFBiz 13.07.03 released

2016-04-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 13.07.03". Apache OFBiz™ is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 13.07.03" is a bug

[ANNOUNCE] Apache OFBiz 12.04.06 released

2016-04-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 12.04.06". Apache OFBiz™ is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 12.04.06" is a bug

[ANNOUNCE] Apache OFBiz 13.07.02 released

2015-05-24 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 13.07.02. Apache OFBiz™ is an open source product for the automation of enterprise processes that includes framework components and business applications for ERP (Enterprise Resource Planning), CRM (Customer

[ANNOUNCE] Apache OFBiz 13.07.01 released

2014-10-07 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the release of Apache OFBiz 13.07.01. Apache OFBiz™ is an open source product for the automation of enterprise processes that includes framework components and business applications: http://ofbiz.apache.org/ Apache OFBiz 13.07.01 is the first

[ANNOUNCE] Apache OFBiz 11.04.06 released

2014-09-10 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 11.04.06. Apache OFBiz™ is an open source product for the automation of enterprise processes that includes framework components and business applications for ERP (Enterprise Resource Planning), CRM (Customer

[ANNOUNCE] Apache OFBiz 12.04.05 released

2014-09-10 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 12.04.05. Apache OFBiz™ is an open source product for the automation of enterprise processes that includes framework components and business applications for ERP (Enterprise Resource Planning), CRM (Customer

[ANNOUNCE] Apache OFBiz 12.04.04 released

2014-08-19 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 12.04.04. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 12.04.04 is a bug fix release for

[ANNOUNCE] Apache OFBiz 12.04.03 released

2014-06-19 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 12.04.03. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 12.04.03 is a bug fix release for

[ANNOUNCE] Apache OFBiz 10.04.06 released

2013-07-20 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 10.04.06. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 10.04.06 is the last bug fix release

[CVE-2013-2137] Apache OFBiz XSS vulnerability in the View Log screen of the Webtools application

2013-07-20 Thread Jacopo Cappellato
CVE-2013-2137 - Apache OFBiz XSS vulnerability in the View Log screen of the Webtools application Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: XSS vulnerability in the View Log

[CVE-2013-2250] Apache OFBiz Nested expression evaluation allows remote users to execute arbitrary UEL functions in OFBiz

2013-07-20 Thread Jacopo Cappellato
CVE-2013-2250 - Apache OFBiz Nested expression evaluation allows remote users to execute arbitrary UEL functions in OFBiz Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: Parameter

[ANNOUNCE] Apache OFBiz 11.04.03 released

2013-07-20 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 11.04.03. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 11.04.03 is a bug fix release for

[ANNOUNCE] Apache OFBiz 12.04.01 released

2013-04-02 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 12.04.01. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 12.04.01 is the first release of the

[ANNOUNCE] Apache OFBiz 10.04.05 released

2013-01-18 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 10.04.05. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 10.04.05 is a bug fix release for

[ANNOUNCE] Apache OFBiz 11.04.01 released

2012-11-18 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 11.04.01. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...). Apache OFBiz 11.04.01 is the first release of the 11.04 series and contains

[ANNOUNCE] Apache OFBiz 10.04.03 released

2012-10-19 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release Apache OFBiz 10.04.03. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 10.04.03 is a bug fix release for

[ANNOUNCE] Apache OFBiz 10.04.02 released

2012-04-15 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the release Apache OFBiz 10.04.02. Apache OFBiz is an open source enterprise automation software project (ERP, CRM, E-Business / E-Commerce, MRP, SCM, CMMS/EAM...): http://ofbiz.apache.org/ Apache OFBiz 10.04.02 is a bug fix release for the

[ANNOUNCE] Apache OFBiz 09.04.02 released

2012-02-26 Thread Jacopo Cappellato
/download.html Kind regards, Jacopo Cappellato signature.asc Description: Message signed with OpenPGP using GPGMail

Apache OFBiz 10.04 released

2011-01-24 Thread Jacopo Cappellato
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The Apache Open For Business Project (Apache OFBiz) releases a new version of its software package. On the 19th of January, 2011 the Apache OFBiz community released a new version of its software package: Apache OFBiz 10.04. This new version