CVE-2019-12425: Apache OFBiz

High severity, CVSS 7.5. EPSS: 4.8% chance of exploitation in the next 30 days.

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

Affected products

  • Apache OFBiz: version 17.12.01 only

Published 2020-04-30. Last modified 2026-06-17.