Sploitus

CVE-2021-30128

3 known exploits for CVE-2021-30128

Apache OFBiz has unsafe deserialization prior to 17.12.07 version

Affected products
Apache Ofbiz
Apache Ofbiz
< 17.12.07
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
81.2% (100th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2021-04-27

Workaround

Upgrade to at least 17.12.07 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12212 & OFBIZ-12221

CVE-2021-30128 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2021-30128

Proof-of-concept code and exploit modules indexed by Sploitus