Re: Applying patch for ofbiz 18.12.06

2022-09-02 Thread Avijit Bose
Hi Jac, Your message is not clear. Request...pls clarify it clearly how to apply patch for individual cases or for all items together. regards Avijit On Fri, Sep 2, 2022 at 5:21 PM Jacques Le Roux wrote: > Hi, > > You need at least the Sub-task (related to security) and Bug lists here: >

How DB GL Account is determined when receiving a payment

2022-09-02 Thread Emad Radwan
Hello Community, While trying to trace the logic to determine the subject issue I came thru the following service, the CR part of the transaction is more clearer as glAccountId is derived from PaymentGlAccountTypeMap the depit part of the transaction is marked by a TODO as in the following! The

Re: Questions regarding purchase orders

2022-09-02 Thread Emad Radwan
Many thanks Rishi > On 1 Sep 2022, at 8:28 PM, Rishi Solanki wrote: > > Dear Emad, > If you notice then Shipment is Purchase Shipment and Item Issuance is link > with inventory item. Shipment will be incoming shipment and with item > issuance inventory received against that order. > > Rishi

Re: Applying patch for ofbiz 18.12.06

2022-09-02 Thread Jacques Le Roux
Hi, You need at least the Sub-task (related to security) and Bug lists here: https://ofbiz.apache.org/release-notes-18.12.06.html For the rest it's up to you... HTH Jacques Le 02/09/2022 à 12:54, Avijit Bose a écrit : Hi, Presently I am using 18.12.05. All applications are set. I wish not

Applying patch for ofbiz 18.12.06

2022-09-02 Thread Avijit Bose
Hi, Presently I am using 18.12.05. All applications are set. I wish not to install 18.12.06 afresh and new. I am thinking of applying patch to upgrade from 18.12.05 to 18.12.06. Please let us know how to apply patches correctly with patch files. regards Avijit

Re: Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-02 Thread Avijit Bose
Hi Jacques, Presently I am using 18.12.05. All applications are set. I wish not to install 18.12.06 afresh and new. I am thinking of applying patch to upgrade from 18.12.05 to 18.12.06. Please let us know how to apply patches correctly with patch files. regards Avijit On Fri, Sep 2, 2022 at

AW: Sort Menu

2022-09-02 Thread Ingo Wolfmayr
Hi Jacques, perfect. Thanks, Ingo -Ursprüngliche Nachricht- Von: Jacques Le Roux Gesendet: Freitag, 2. September 2022 10:59 An: user@ofbiz.apache.org Betreff: Re: Sort Menu Hi Ingo, Yes, each webapp has a position attribute in its ofbiz-component.xml file Jacques Le 02/09/2022 à

Re: Sort Menu

2022-09-02 Thread Jacques Le Roux
Hi Ingo, Yes, each webapp has a position attribute in its ofbiz-component.xml file Jacques Le 02/09/2022 à 10:31, Ingo Wolfmayr a écrit : Hi, is there a way to sort the main menu? Best regards, Ingo

Sort Menu

2022-09-02 Thread Ingo Wolfmayr
Hi, is there a way to sort the main menu? Best regards, Ingo

Apache OFBiz - Unauth Stored XSS (CVE-2022-25370)

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Java Deserialization via RMI Connection (CVE-2022-29063)

2022-09-02 Thread Jacques Le Roux
Severity: Low (only on shared servers) Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The OFBiz Solr plugin is configured by default to automatically make a RMI request on localhost, port 1099. By hosting a malicious RMI server on

Apache OFBiz - Regular Expression Denial of Service (ReDoS) [CVE-2022-29158]

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users.

Subject: Apache OFBiz - Server-Side Template Injection (CVE-2022-25813)

2022-09-02 Thread Jacques Le Roux
Severity: High (SSTI then possible RCE) Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: As an ecommerce anonymous client, an external attacker can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a