← back
CVE-2021-30128observed exploitation

Unsafe deserialization in Apache OFBiz

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 81%
from disclosure to weapon2 days
Published on NVDApr 27
1st PoC+2d
VulnCheck+1882d
exploitation probability
81%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.