CVE-2016-2170: Apache OFBiz
Critical severity, CVSS 9.8. EPSS: 12.7% chance of exploitation in the next 30 days.
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Affected products
- Apache OFBiz: from 12.04, before 12.04.06 (fixed in 12.04.06); from 13.07, before 13.07.03 (fixed in 13.07.03)
Published 2016-04-12. Last modified 2026-06-17.