cbcvebase.
CVE-2019-0189
published 2019-09-11

CVE-2019-0189: The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
23.71%
97.6th percentile
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz
apacheofbiz
apacheofbiz>= 16.11.01 < 16.11.0616.11.06

Detection & IOCsextracted from sources · hover to see the quote

urlwebtools/control/httpService
  • Monitor HTTP requests targeting the 'webtools/control/httpService' endpoint for a 'serviceContext' request parameter, which is passed to the 'deserialize' method of 'XmlSerializer' and can trigger Java deserialization code execution.
  • Inspect deserialization payloads for gadget chains originating from 'commons-beanutils' or 'commons-fileupload' libraries, as Apache OFBiz is exploitable via both dependencies.
  • Flag Java deserialization activity (e.g., ObjectInputStream usage) triggered through the OFBiz HttpEngine request pipeline.
  • ·Vulnerability affects Apache OFBiz versions 16.11.01 through 16.11.05 only; version 16.11.06 and later are patched.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.