QID 375399
Date Published: 2021-03-24
QID 375399: Apache OFBiz Unsafe Deserialization Vulnerability (OFBIZ-12167)
Apache OFBiz is an open source enterprise resource planning (ERP) system.
XML-RPC in Apache OFBiz request is affected by unsafe deserialization issues.
Affected Versions:
Apache OFBiz before 17.12.06
QID Detection Logic (authenticated):
Operating System: Linux
The checks the running process information to check Apache OFBiz install path and then checks if the fix has been applied .
Successful exploitation will allow to perform remote code execution.
Solution
Customers are advised to update to the latest version of Apache OFBiz.
Vendor References
- OFBIZ-12167 -
issues.apache.org/jira/browse/OFBIZ-12167
CVEs related to QID 375399
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache OFBiz |
|