CVE-2021-26295 – RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
https://notcve.org/view.php?id=CVE-2021-26295
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz. Apache OFBiz, presenta una deserialización no segura versiones anteriores a 17.12.06. Un atacante no autenticado puede usar esta vulnerabilidad para apoderarse con éxito de Apache OFBiz • https://github.com/yumusb/CVE-2021-26295 https://github.com/dskho/CVE-2021-26295 https://github.com/rakjong/CVE-2021-26295-Apache-OFBiz https://github.com/coolyin001/CVE-2021-26295-- http://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-Deserialization.html https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3E https://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org%3E https: • CWE-502: Deserialization of Untrusted Data •
CVE-2020-9496 – ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
https://notcve.org/view.php?id=CVE-2020-9496
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03 La petición de XML-RPC es vulnerable a problemas de deserialización no segura y Cross-Site Scripting en Apache OFBiz versión 17.12.03 • https://www.exploit-db.com/exploits/50178 https://github.com/dwisiswant0/CVE-2020-9496 https://github.com/g33xter/CVE-2020-9496 https://github.com/s4dbrd/CVE-2020-9496 https://github.com/Ly0nt4r/CVE-2020-9496 https://github.com/cyber-niz/CVE-2020-9496 https://github.com/ambalabanov/CVE-2020-9496 https://github.com/birdlinux/CVE-2020-9496 https://github.com/Vulnmachines/apache-ofbiz-CVE-2020-9496 http://packetstormsecurity.com/files/158887/Apache-OFBiz-XML-RPC-Java-Deseri • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-502: Deserialization of Untrusted Data •
CVE-2020-13923
https://notcve.org/view.php?id=CVE-2020-13923
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 Vulnerabilidad de IDOR en la funcionalidad order processing del componente ecommerce de Apache OFBiz versiones anteriores a 17.12.04 • https://lists.apache.org/thread.html/r0a0a701610b3bcdf14634047313adab3f1628bb9aa55cf29cd262ef5%40%3Ccommits.ofbiz.apache.org%3E https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3E https://lists.apache.org/thread.html/r2e669797c1ea08562253239d2dc4192d951945e0c36cb0754f5394a6%40%3Cannounce.apache.org%3E https://lists.apache.org/thread.html/rac7e36c3daa60dd4b813f72942921b4fad71da821480ebcea96ecea1%40%3Cnotifications.ofbiz.apache.org%3E https://s.apache.org/chokl • CWE-639: Authorization Bypass Through User-Controlled Key •