OFBiz allows an unauthenticated attacker to send arbitrary requests to perform lookups on the internal network which is otherwise not accessible externally. An attacker may use this feature to perform SSRF (server-side request forgery) attacks on the server.
The impact varies depending on the environment.
Upgrade to the latest version of OFBiz

You can search and find all vulnerabilities
