Source |
The Hacker News |
Identifiant |
2515994 |
Date de publication |
2021-03-22 01:34:44 (vue: 2021-03-22 09:05:40) |
Titre |
Critical RCE Vulnerability Found in Apache OFBiz ERP Software-Patch Now |
Texte |
The Apache Software Foundation on Friday addressed a high severity vulnerability in Apache OFBiz that could have allowed an unauthenticated adversary to remotely seize control of the open-source enterprise resource planning (ERP) system.
Tracked as CVE-2021-26295, the flaw affects all versions of the software prior to 17.12.06 and employs an "unsafe deserialization" as an attack vector to permit |
Notes |
|
Envoyé |
Oui |
Condensat |
06 and 2021 26295 addressed adversary affects all allowed apache as cve attack control could critical deserialization employs enterprise erp flaw found foundation friday have high now ofbiz open patch permit planning prior rce remotely resource seize severity software source system to 17 tracked unauthenticated unsafe vector versions vulnerability |
Tags |
Vulnerability
|
Stories |
|
Move |
|