Apache OFBiz RMI deserializes Arbitrary Code Execution

By
Rejah Rehim
Published on
16 Jun 2021
Vulnerability

Apache OFBiz is an open source enterprise resource planning (ERP) service that incorporates a collection of software to automate business operations in enterprise environments. It is a web platform that runs on Java. OFBiz is also one of the platforms affected by a Java serialisation bug found and publicly disclosed in 2015. Apache OFBiz using inefficient deserialization. This vulnerability helps an unauthenticated attacker to potentially gain ownership of Apache OFBiz. Prior to 17.12.06, deserialization of unsecured data in Apache OFBiz enabled remote hackers to run malicious scripts.

Mitigation / Precaution

  • To patch this issue, upgrade the Apache OFBiz package to the most recent version.
Automated human-like penetration testing for your web apps & APIs
Teams using Beagle Security are set up in minutes, embrace release-based CI/CD security testing and save up to 65% with timely remediation of vulnerabilities. Sign up for a free account to see what it can do for you.

Written by
Rejah Rehim
Rejah Rehim
Co-founder, Director
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days
Find surface-level website security issues in under a minute
Free website security assessment
Experience the power of automated penetration testing & contextual reporting.