CVE-2016-2170
12.04.2016, 14:59
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.Enginsight
Vendor | Product | Version |
---|---|---|
apache | ofbiz | 12.04 ≤ 𝑥 < 12.04.06 |
apache | ofbiz | 13.07 ≤ 𝑥 < 13.07.03 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References