CVE-2021-26295: RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
Published Mar 22, 2021
·Updated
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
Affected Software
1 affected component
Apache OFBiz<17.12.06
Remediation
Event History
Mar 22, 2021
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-26295?
CVE-2021-26295 is a vulnerability in Apache OFBiz that allows an unauthenticated attacker to perform unsafe deserialization and potentially take over the system.
2
How severe is CVE-2021-26295?
CVE-2021-26295 has a severity rating of 9.8 (critical).
3
How does CVE-2021-26295 affect Apache OFBiz?
CVE-2021-26295 affects Apache OFBiz versions prior to 17.12.06 and can be exploited by an unauthenticated attacker.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-26295?
The CWE ID for CVE-2021-26295 is 502.
5
How can CVE-2021-26295 be fixed?
To fix CVE-2021-26295, users should update Apache OFBiz to version 17.12.06 or later.