RULE(RULE ID:333531)

Rule General Information
Release Date: 2021-05-11
Rule Name: Apache OFBiz Remote Code Execution Vulnerability (CVE-2021-30128)
Severity:
CVE ID:
Rule Protection Details
Description: Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://www.openwall.com/lists/oss-security/2021/04/27/5
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d@%3Ccommits.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cdev.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743@%3Cannounce.apache.org%3E
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://lists.apache.org/thread.html/rb3f5cd65f3ddce9b9eb4d6ea6e2919933f0f89b15953769d11003743%40%3Cdev.ofbiz.apache.org%3E