CVE-2021-30128: Unsafe deserialization in Apache OFBiz
Published Apr 27, 2021
·Updated
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
Affected Software
1 affected component
Apache OFBiz<17.12.07
Remediation
Patch Available
Event History
Apr 27, 2021
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-30128?
CVE-2021-30128 is a vulnerability in Apache OFBiz that allows for unsafe deserialization prior to version 17.12.07.
2
How severe is CVE-2021-30128?
CVE-2021-30128 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2021-30128 affect Apache OFBiz?
CVE-2021-30128 affects Apache OFBiz versions prior to 17.12.07, allowing for unsafe deserialization.
4
How can I fix CVE-2021-30128?
To fix CVE-2021-30128, update Apache OFBiz to version 17.12.07 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-30128?
The Common Weakness Enumeration (CWE) ID for CVE-2021-30128 is 502.