CVE-2021-26295
published 2021-03-22CVE-2021-26295: Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
97.82%
99.9th percentile
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 17.12.06 | 17.12.06 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable unauthenticated endpoint is /webtools/control/SOAPService — monitor HTTP POST requests to this path for unexpected or malformed SOAP/serialized Java payloads, especially from unauthenticated sources. ↗
- →Responses containing the string 'errorMessage' in the body combined with the 'OFBiz.Visitor=' cookie in the response header are indicative of a successful interaction with the vulnerable OFBiz endpoint.
- →DNS callback interaction can be used to confirm blind exploitation of the deserialization vulnerability — monitor for out-of-band DNS lookups triggered by payloads delivered to the SOAPService endpoint.
- →The exploit uses a Java gadget chain for DNS interaction; detect use of Java deserialization gadget generation patterns (e.g., ysoserial-style payloads) in HTTP request bodies targeting OFBiz.
- ·The vulnerability affects all Apache OFBiz releases before 17.12.06; the fix was introduced in 17.12.06 (commit af9ed4e). Ensure detection rules are scoped to unpatched instances running versions prior to 17.12.06. ↗
- ·The SOAP endpoint /webtools/control/SOAPService is unauthenticated, meaning no session token or credential is required to trigger the deserialization — authentication-based detections will not catch this attack. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
vendor_apache9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache ofbiz: CVE-2021-26295
vendor_apache·CVSS 9.8
CVE-2021-26295 [CRITICAL] Apache ofbiz: CVE-2021-26295
Apache ofbiz: CVE-2021-26295
; affected all releases before 17.12.07; fixed in 17.12.06 with commit af9ed4e .
GHSA
GHSA-hp7h-f9pw-x5wj: Apache OFBiz has unsafe deserialization prior to 17
ghsa_unreviewed·2022-05-24
CVE-2021-26295 [CRITICAL] CWE-502 GHSA-hp7h-f9pw-x5wj: Apache OFBiz has unsafe deserialization prior to 17
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
VulnCheck
Apache OFBiz Deserialization of Untrusted Data
vulncheck·2021·CVSS 9.8
CVE-2021-26295 [CRITICAL] Apache OFBiz Deserialization of Untrusted Data
Apache OFBiz Deserialization of Untrusted Data
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
Affected: Apache OFBiz
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-05&host_type=src&vulnerability=cve-2021-26295; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-06&host_type=src&vulnerability=cve-2021-26295; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-19&host_type=src&vulnerability=cve-2021
No detection rules found.
Nuclei
Apache OFBiz <17.12.06 - Arbitrary Code Execution
nuclei·CVSS 9.8
CVE-2021-26295 [CRITICAL] Apache OFBiz <17.12.06 - Arbitrary Code Execution
Apache OFBiz
{{generate_java_gadget("dns", "https://{{interactsh-url}}", "hex")}}
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "dns"
- type: word
part: body
words:
- "errorMessage"
condition: and
- type: word
part: header
words:
- "OFBiz.Visitor="
# digest: 4a0a00473045022100f2ade828e120c498cb39bbcacdcc458800b04199a53bef9cb9da7812cd3e4a0c02200b2c1b73fd6106a168abfd98e599879c2c3624e754456e205835fed1a76a3730:922c64590222798bb761d5b6d8e72950
Metasploit
Apache OFBiz SOAP Java Deserialization
metasploit
Apache OFBiz SOAP Java Deserialization
Apache OFBiz SOAP Java Deserialization
This module exploits a Java deserialization vulnerability in Apache OFBiz's unauthenticated SOAP endpoint /webtools/control/SOAPService for versions prior to 17.12.06.
http://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-Deserialization.htmlhttps://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r3c1802eaf34aa78a61b4e8e044c214bc94accbd28a11f3a276586a31%40%3Cuser.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd1dc51a13d4e244%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r6e4579c4ebf7efeb462962e359501c6ca4045687f12212551df2d607%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc80552b84ca2599%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f67b90434e4467a%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9789a2a7d9cccf6%40%3Cdev.ofbiz.apache.org%3Ehttp://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-Deserialization.htmlhttps://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r3c1802eaf34aa78a61b4e8e044c214bc94accbd28a11f3a276586a31%40%3Cuser.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd1dc51a13d4e244%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r6e4579c4ebf7efeb462962e359501c6ca4045687f12212551df2d607%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc80552b84ca2599%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f67b90434e4467a%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9789a2a7d9cccf6%40%3Cdev.ofbiz.apache.org%3E
2021-03-22
Published
Exploited in the wild