Severity:
High, possible RCE
Vendor:
The Apache Software Foundation
Versions Affected:
OFBiz versions prior to 17.12.07
Description:
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Mitigation:
Upgrade to at least 17.12.07
or apply patches at
https://issues.apache.org/jira/browse/OFBIZ-12212 & OFBIZ-12221
Credit:
Litch1 from the Security Team of Alibaba Cloud <
[hidden email]>
References:
http://ofbiz.apache.org/download.html#vulnerabilities