CVE-2016-2170
published 2016-04-12CVE-2016-2170: Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.68%
95.8th percentile
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | >= 12.04 < 12.04.06 | 12.04.06 |
| apache | ofbiz | >= 13.07 < 13.07.03 | 13.07.03 |
Detection & IOCsextracted from sources · hover to see the quote
- ·Vulnerability affects Apache OFBiz versions 12.04.x before 12.04.06 and 13.07.x before 13.07.03; exploitation is via crafted serialized Java object leveraging Apache Commons Collections library ↗
- ·Affected releases confirmed as 13.07.02 and earlier (13.07.*) and 12.04.05 and earlier (12.04.*); fixed versions are 13.07.03 and 12.04.06 ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache ofbiz: CVE-2016-2170
vendor_apache·CVSS 9.8
CVE-2016-2170 [CRITICAL] Apache ofbiz: CVE-2016-2170
Apache ofbiz: CVE-2016-2170
; affected releases: 13.07.02 and earlier versions (13.07.*), 12.04.05 and earlier versions (12.04.*); fixed in 13.07.03 and 12.04.06
GHSA
GHSA-39hj-fwhh-gc6w: Apache OFBiz 12
ghsa_unreviewed·2022-05-13
CVE-2016-2170 [CRITICAL] CWE-20 GHSA-39hj-fwhh-gc6w: Apache OFBiz 12
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
No detection rules found.
No public exploits indexed.
arXiv
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
arxiv_fulltext·2022-08-17
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
[Imen Sayar]Imen Sayar^
[email protected]
University of Toulouse
Blagnac
France
31070
^ Part of this research was conducted when Imen Sayar was at the University of Luxembourg
[Alexandre Bartel]Alexandre Bartel^*
[email protected]
Umeå University
MIT-Huset
Umeå
Sweden
^*Part of this research was conducted when Alexandre Bartel was at the University of Luxembourg and the University of Copenhagen.
Eric Bodden
[email protected]
Paderborn University
Paderborn
Germany
Yves Le Traon
[email protected]
University of Luxembourg
6, rue Richard Coudenhove-Kalergi
Kirchberg Campus
Luxembourg
L-1359
## Abstract
Nowadays, an increasing number of applications uses deserializatio
arXiv
A Non-Intrusive and Context-Based Vulnerability Scoring Framework for Cloud Services
arxiv_fulltext·2016-12-07
A Non-Intrusive and Context-Based Vulnerability Scoring Framework for Cloud Services
-1emA Non-Intrusive and Context-Based Vulnerability Scoring
Framework for Cloud Services
Hao Zhuang, Florian Pydde
EPFL
## Abstract
Understanding the severity of vulnerabilities within
cloud services is particularly important
for today's service administrators.
Although many systems, , CVSS, have been built to evaluate
and score the severity of vulnerabilities for administrators,
the scoring schemes employed by these systems fail to take into account
the contextual information of specific services having
these vulnerabilities, such as what roles they play in a particular
service. Such a deficiency makes resulting scores unhelpful.
This paper presents a practical framework, ,
that offers automatic and contextual scoring mechanism
to evaluate the severity of vulnerabilities
for a particu
http://ofbiz.apache.org/download.html#vulnerabilitieshttp://packetstormsecurity.com/files/136639/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.htmlhttp://www.securityfocus.com/archive/1/538034/100/0/threadedhttp://www.securitytracker.com/id/1035513https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07https://cwiki.apache.org/confluence/display/OFBIZ/The+infamous+Java+serialization+vulnerabilityhttps://issues.apache.org/jira/browse/OFBIZ-6726https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd1dc51a13d4e244%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc80552b84ca2599%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f67b90434e4467a%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9789a2a7d9cccf6%40%3Cdev.ofbiz.apache.org%3Ehttp://ofbiz.apache.org/download.html#vulnerabilitieshttp://packetstormsecurity.com/files/136639/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.htmlhttp://www.securityfocus.com/archive/1/538034/100/0/threadedhttp://www.securitytracker.com/id/1035513https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07https://cwiki.apache.org/confluence/display/OFBIZ/The+infamous+Java+serialization+vulnerabilityhttps://issues.apache.org/jira/browse/OFBIZ-6726https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd1dc51a13d4e244%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc80552b84ca2599%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f67b90434e4467a%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9789a2a7d9cccf6%40%3Cdev.ofbiz.apache.org%3E
2016-04-12
Published