CVE-2021-26295
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
- Affected products
- Apache Ofbiz
- Apache Ofbiz
- < 17.12.06
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 97.8% (100th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2021-03-22
Workaround
Upgrade to at least 17.12.06 or apply the patch at https://github.com/apache/ofbiz-framework/commit/af9ed4e/
CVE-2021-26295 at NVD
8 known exploits for CVE-2021-26295
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Restriction of XML External Entity Reference in Apache Solr
Exploit for Deserialization of Untrusted Data in Apache Ofbiz
Apache OFBiz SOAP Java Deserialization Exploit
Apache OFBiz SOAP Java Deserialization
Exploit for Deserialization of Untrusted Data in Apache Ofbiz
Exploit for Deserialization of Untrusted Data in Apache Ofbiz
Apache OFBiz RCE漏洞(CVE-2021-26295)
Apache OFBiz SOAP Java Deserialization