Apache OFBiz is an open source enterprise resource planning (ERP) service that incorporates a collection of software to automate business operations in enterprise environments. It is a web platform that runs on Java. OFBiz is also one of the platforms affected by a Java serialisation bug found and publicly disclosed in 2015. Apache OFBiz using inefficient deserialization. This vulnerability helps an unauthenticated attacker to potentially gain ownership of Apache OFBiz. Prior to 17.12.06, deserialization of unsecured data in Apache OFBiz enabled remote hackers to run malicious scripts.