Vulnerability Description
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ofbiz | < 17.12.06 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-DeserializatiExploitThird Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4d
- https://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723
- https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c1
- https://lists.apache.org/thread.html/r3c1802eaf34aa78a61b4e8e044c214bc94accbd28aMailing ListPatchVendor Advisory
- https://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd
- https://lists.apache.org/thread.html/r6e4579c4ebf7efeb462962e359501c6ca4045687f1
- https://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199
- https://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a
- https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb
- https://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc
- https://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f
- https://lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9
- http://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-DeserializatiExploitThird Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4d
FAQ
What is CVE-2021-26295?
CVE-2021-26295 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
How severe is CVE-2021-26295?
CVE-2021-26295 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-26295?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Ofbiz.