QID 730862
Date Published: 2023-08-10
QID 730862: Apache OFBiz Deserialization Vulnerability
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Affected versions
Apache OFBiz prior to 17.12.07
QID Detection Logic (Un-authenticated)
This qid sends request to /webtools/control/SOAPService to check for error string.
On successful exploitation it allows remote code execution.
Solution
Upgrade to at least 17.12.07. Refer to downloads for updates and patch information.
Vendor References
- OFBIZ-12212 -
issues.apache.org/jira/browse/OFBIZ-12212
CVEs related to QID 730862
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Release Notes 17.12.07 |
|