VYPR
Critical severity9.8NVD Advisory· Published Apr 12, 2016· Updated May 6, 2026

CVE-2016-2170

CVE-2016-2170

Description

Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

Affected products

1
  • cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
    Range: >=12.04,<12.04.06

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.