← back
CVE-2021-29200

RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 55%
exploitation probability
55%top 1% of all CVEs
observed exploitation
nono source reports it
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack