CVE-2016-2170: Apache OFBiz information disclosure vulnerability Apr 08 2016 08:41PM
jleroux (at) apache (dot) org [email concealed] (jleroux apache org)
CVE-2016-2170: Apache OFBiz information disclosure vulnerability

Severity: Important

The Apache Software Foundation

Versions Affected:
Apache OFBiz 13.07.02 and 13.07.01
Apache OFBiz 12.04.05 and earlier releases in the series (12.04.*)
The unsupported releases 11.04.*, 10.04.* and 09.04 versions are also affected but not fixed.

The infamous Java serialization vulnerability

13.07.* users should upgrade to 13.07.03
12.04.05 users should upgrade to 12.04.06 (Note though that in 12.04.06 RMI is not deactivated so you should use the recommended remediation: notsoserial)

This infamous issue was confirmed to be an issue in OFBiz by the OFBiz team, due to two external Java libraries and RMI usage.

Apart when using RMI with 12.04.03 version nothing is needed. But with any version, if you use JNDI, JMX or Spring and maybe other Java classes,
please check the references (hint: use notsoserial with your own whitelist)



[ reply ]


Privacy Statement
Copyright 2010, SecurityFocus