Apache OFBiz RMI deserializes Arbitrary Code Execution

Published on 16 Jun 2021
Vulnerability

Apache OFBiz is an open source enterprise resource planning (ERP) service that incorporates a collection of software to automate business operations in enterprise environments. It is a web platform that runs on Java. OFBiz is also one of the platforms affected by a Java serialisation bug found and publicly disclosed in 2015. Apache OFBiz using inefficient deserialization. This vulnerability helps an unauthenticated attacker to potentially gain ownership of Apache OFBiz. Prior to 17.12.06, deserialization of unsecured data in Apache OFBiz enabled remote hackers to run malicious scripts.

Mitigation / Precaution

  • To patch this issue, upgrade the Apache OFBiz package to the most recent version.
Rejah Rehim
Written by
Co-founder, Director

Rejah brings more than 12 years of industry experience in Information Technology. He is a fervent security enthusiast and serves as a Project Leader at OWASP Foundation, and Commander (Hon.) at Kerala Police. He has authored two books titled “Effective Python Penetration Testing” and “Python Penetration Testing Cookbook” and is the creator of 9 Mozilla add-ons.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo