Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Description
Published by the National Vulnerability Database
Apr 12, 2016
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 12, 2025
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
References