ZeroHour

CVE-2021-26295

PoC
CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
Modified
Description

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

Vendors
apache
Products
ofbiz
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news