CVE-2021-29200: RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
Published Apr 27, 2021
·Updated
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Affected Software
1 affected component
Apache OFBiz<17.12.07
Remediation
Patch Available
Event History
Apr 27, 2021
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-29200?
CVE-2021-29200 is a vulnerability in Apache OFBiz that allows an unauthenticated user to perform a remote code execution (RCE) attack.
2
How severe is CVE-2021-29200?
CVE-2021-29200 has a severity rating of critical with a CVSS score of 9.8.
3
How does CVE-2021-29200 affect Apache OFBiz?
CVE-2021-29200 affects Apache OFBiz versions prior to 17.12.07 and can be exploited by an unauthenticated user.
4
How can an unauthenticated user exploit CVE-2021-29200?
An unauthenticated user can exploit CVE-2021-29200 by performing a remote code execution (RCE) attack.
5
Is there a fix available for CVE-2021-29200?
Yes, the fix for CVE-2021-29200 is to upgrade to Apache OFBiz version 17.12.07 or newer.