Critical severity9.8NVD Advisory· Published Apr 12, 2016· Updated May 6, 2026
CVE-2016-2170
CVE-2016-2170
Description
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- ofbiz.apache.org/download.htmlnvdPatchVendor Advisory
- blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04nvdPatchVendor Advisory
- issues.apache.org/jira/browse/OFBIZ-6726nvdPatchVendor Advisory
- packetstormsecurity.com/files/136639/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.htmlnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/538034/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1035513nvdThird Party AdvisoryVDB Entry
- blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07nvdVendor Advisory
- cwiki.apache.org/confluence/display/OFBIZ/The+infamous+Java+serialization+vulnerabilitynvdVendor Advisory
- lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.apache.org%3Envd
- lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org%3Envd
- lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd1dc51a13d4e244%40%3Cnotifications.ofbiz.apache.org%3Envd
- lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.apache.org%3Envd
- lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.apache.org%3Envd
- lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc80552b84ca2599%40%3Cnotifications.ofbiz.apache.org%3Envd
- lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f67b90434e4467a%40%3Cdev.ofbiz.apache.org%3Envd
- lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9789a2a7d9cccf6%40%3Cdev.ofbiz.apache.org%3Envd
News mentions
0No linked articles in our index yet.