Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2021-29200
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
Exploit prediction scoring system (EPSS) score
EPSS Score
0.93
EPSS Ranking
99.8%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
7.5
References
http://www.openwall.com/lists/oss-security/2021/04/27/4
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda%40%3Cnotifications.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cannounce.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cuser.ofbiz.apache.org%3E
http://www.openwall.com/lists/oss-security/2021/04/27/4
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda%40%3Cnotifications.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cannounce.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cuser.ofbiz.apache.org%3E
Products affected by CVE-2021-29200
Apache
»
Ofbiz
»
Version:
N/A
cpe:2.3:a:apache:ofbiz:-
Apache
»
Ofbiz
»
Version:
09.04
cpe:2.3:a:apache:ofbiz:09.04
Apache
»
Ofbiz
»
Version:
09.04.01
cpe:2.3:a:apache:ofbiz:09.04.01
Apache
»
Ofbiz
»
Version:
10.04
cpe:2.3:a:apache:ofbiz:10.04
Apache
»
Ofbiz
»
Version:
10.04.01
cpe:2.3:a:apache:ofbiz:10.04.01
Apache
»
Ofbiz
»
Version:
10.04.02
cpe:2.3:a:apache:ofbiz:10.04.02
Apache
»
Ofbiz
»
Version:
10.04.03
cpe:2.3:a:apache:ofbiz:10.04.03
Apache
»
Ofbiz
»
Version:
10.04.04
cpe:2.3:a:apache:ofbiz:10.04.04
Apache
»
Ofbiz
»
Version:
10.04.05
cpe:2.3:a:apache:ofbiz:10.04.05
Apache
»
Ofbiz
»
Version:
10.04.06
cpe:2.3:a:apache:ofbiz:10.04.06
Apache
»
Ofbiz
»
Version:
11.04
cpe:2.3:a:apache:ofbiz:11.04
Apache
»
Ofbiz
»
Version:
11.04.01
cpe:2.3:a:apache:ofbiz:11.04.01
Apache
»
Ofbiz
»
Version:
11.04.02
cpe:2.3:a:apache:ofbiz:11.04.02
Apache
»
Ofbiz
»
Version:
11.04.03
cpe:2.3:a:apache:ofbiz:11.04.03
Apache
»
Ofbiz
»
Version:
11.04.04
cpe:2.3:a:apache:ofbiz:11.04.04
Apache
»
Ofbiz
»
Version:
11.04.05
cpe:2.3:a:apache:ofbiz:11.04.05
Apache
»
Ofbiz
»
Version:
11.04.06
cpe:2.3:a:apache:ofbiz:11.04.06
Apache
»
Ofbiz
»
Version:
12.04
cpe:2.3:a:apache:ofbiz:12.04
Apache
»
Ofbiz
»
Version:
12.04.01
cpe:2.3:a:apache:ofbiz:12.04.01
Apache
»
Ofbiz
»
Version:
12.04.02
cpe:2.3:a:apache:ofbiz:12.04.02
Apache
»
Ofbiz
»
Version:
12.04.03
cpe:2.3:a:apache:ofbiz:12.04.03
Apache
»
Ofbiz
»
Version:
12.04.04
cpe:2.3:a:apache:ofbiz:12.04.04
Apache
»
Ofbiz
»
Version:
12.04.05
cpe:2.3:a:apache:ofbiz:12.04.05
Apache
»
Ofbiz
»
Version:
12.04.06
cpe:2.3:a:apache:ofbiz:12.04.06
Apache
»
Ofbiz
»
Version:
13.07
cpe:2.3:a:apache:ofbiz:13.07
Apache
»
Ofbiz
»
Version:
13.07.01
cpe:2.3:a:apache:ofbiz:13.07.01
Apache
»
Ofbiz
»
Version:
13.07.02
cpe:2.3:a:apache:ofbiz:13.07.02
Apache
»
Ofbiz
»
Version:
13.07.03
cpe:2.3:a:apache:ofbiz:13.07.03
Apache
»
Ofbiz
»
Version:
16.11.01
cpe:2.3:a:apache:ofbiz:16.11.01
Apache
»
Ofbiz
»
Version:
16.11.02
cpe:2.3:a:apache:ofbiz:16.11.02
Apache
»
Ofbiz
»
Version:
16.11.03
cpe:2.3:a:apache:ofbiz:16.11.03
Apache
»
Ofbiz
»
Version:
16.11.04
cpe:2.3:a:apache:ofbiz:16.11.04
Apache
»
Ofbiz
»
Version:
16.11.05
cpe:2.3:a:apache:ofbiz:16.11.05
Apache
»
Ofbiz
»
Version:
16.11.06
cpe:2.3:a:apache:ofbiz:16.11.06
Apache
»
Ofbiz
»
Version:
16.11.07
cpe:2.3:a:apache:ofbiz:16.11.07
Apache
»
Ofbiz
»
Version:
17.12.01
cpe:2.3:a:apache:ofbiz:17.12.01
Apache
»
Ofbiz
»
Version:
17.12.03
cpe:2.3:a:apache:ofbiz:17.12.03
Apache
»
Ofbiz
»
Version:
17.12.04
cpe:2.3:a:apache:ofbiz:17.12.04
Apache
»
Ofbiz
»
Version:
17.12.05
cpe:2.3:a:apache:ofbiz:17.12.05
Apache
»
Ofbiz
»
Version:
17.12.06
cpe:2.3:a:apache:ofbiz:17.12.06
Apache
»
Ofbiz
»
Version:
9.04
cpe:2.3:a:apache:ofbiz:9.04
Apache
»
Ofbiz
»
Version:
9.04.01
cpe:2.3:a:apache:ofbiz:9.04.01
Apache
»
Ofbiz
»
Version:
9.04.02
cpe:2.3:a:apache:ofbiz:9.04.02
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved