cbcvebase.
CVE-2021-30128
published 2021-04-27

CVE-2021-30128: Apache OFBiz has unsafe deserialization prior to 17.12.07 version

PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
81.08%
99.6th percentile
Apache OFBiz has unsafe deserialization prior to 17.12.07 version

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 17.12.0717.12.07
apacheofbiz
apache_software_foundationapache_ofbiz>= Apache OFBiz < 17.12.0717.12.07

Detection & IOCsextracted from sources · hover to see the quote

sigma
matchers-condition: and
matchers:
- type: word
  part: interactsh_protocol
  words:
  - "dns"

- type: word
  part: body
  words:
  - 'value="errorMessage"'
  • Exploit payload uses Java gadget with DNS callback via interactsh; detect out-of-band DNS interactions triggered from OFBiz server as evidence of successful deserialization exploitation.
  • Response body containing 'value="errorMessage"' combined with a DNS interaction from the target confirms the deserialization vulnerability is triggered.
  • ·Vulnerability affects all Apache OFBiz releases before 17.12.07; upgrade to 17.12.07 or later to remediate.
  • ·The NVD description confirms the unsafe deserialization root cause; no version-specific patch bypass is noted beyond the 17.12.07 fix.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
vendor_apache9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.