S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-8033 Scanner

Detects 'XML External Entity (XXE)' vulnerability in Apache OFBiz affects v. 16.11.01 to 16.11.04.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-8033
7.5
CVSS

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache OFBizby Apache Software Foundation
Apache OFBiz 16.11.01 to 16.11.04
Updated Aug 18, 2026View on NVD →
Detail

Apache OFBiz is an open-source enterprise resource planning (ERP), customer relationship management (CRM), and e-commerce software suite. It provides an integrated framework for managing different aspects of a business, including financials, supply chain, and human resources. The software is widely used by businesses of all sizes for streamlining their operations and improving efficiency.

CVE-2018-8033 is a vulnerability in Apache OFBiz that affects versions 16.11.01 to 16.11.04. It is caused by the HTTP engine's handling of requests for HTTP services via the /webtools/control/httpService endpoint. The vulnerability is due to the presence of external references in the serviceContext parameter, which can trigger a payload that returns secret information from the host. This can lead to unauthorized access to sensitive data, including customer information, financial data, and trade secrets.

Exploiting CVE-2018-8033 can have devastating consequences for businesses. Hackers can use the vulnerability to gain access to confidential information and compromise the integrity of the system. This can lead to financial losses, reputational damage, and legal liabilities. Moreover, once the data is breached, it is challenging to contain the damage, as it can spread quickly and affect not only the company but also its customers and partners.

Thanks to the pro features of the s4e.io platform, businesses can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability scanning and reporting services, along with expert advice and support. By leveraging the power of s4e.io, businesses can stay ahead of the latest threats and protect their assets from cybercriminals.

 

REFERENCES

Solution Advice

To protect against CVE-2018-8033 and other vulnerabilities in Apache OFBiz, businesses can take the following precautions:

  • Apply the latest security patches and updates for the software.
  • Restrict access to the /webtools/control/httpService endpoint, and limit the use of external references in the serviceContext parameter.
  • Use strong passwords and two-factor authentication to secure user accounts and access to the system.
  • Implement network segmentation and firewalls to prevent unauthorized access to critical systems and data.
  • Regularly audit and monitor the system for unusual activity and security breaches.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-8033 scanner - XML External Entity (XXE) vulnerability in Apache OFBiz | S4E