Vulnerability Description
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ofbiz | >= 12.04, < 12.04.06 |
Related Weaknesses (CWE)
References
- http://ofbiz.apache.org/download.html#vulnerabilitiesPatchVendor Advisory
- http://packetstormsecurity.com/files/136639/Apache-OFBiz-13.07.02-13.07.01-InforThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/538034/100/0/threadedThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035513Third Party AdvisoryVDB Entry
- https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04PatchVendor Advisory
- https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07Vendor Advisory
- https://cwiki.apache.org/confluence/display/OFBIZ/The+infamous+Java+serializatioVendor Advisory
- https://issues.apache.org/jira/browse/OFBIZ-6726PatchVendor Advisory
- https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4d
- https://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723
- https://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd
- https://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199
- https://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a
- https://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc
- https://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f
FAQ
What is CVE-2016-2170?
CVE-2016-2170 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections li...
How severe is CVE-2016-2170?
CVE-2016-2170 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-2170?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Ofbiz.