← Vulnerability feed

Vulnerability record · CVE-2020-9496 · published 15 July 2020

CVE-2020-9496: Apache OFBiz XML-RPC unsafe deserialization and XSS

Apache · Ofbiz

Apache OFBiz 17.12.03 exposes XML-RPC endpoints that perform unsafe deserialization of untrusted data and are also vulnerable to cross-site scripting. The deserialization flaw is the serious part: it allows crafted XML-RPC requests to reach Java object deserialization, which is a well-known path to remote code execution. The XSS issue is secondary and requires a victim to interact with a crafted request.

6.1 CVSS 3.1 Medium EPSS 99% · top 0.1% CWE-79 · Cross-site scriptingCWE-502 · Deserialization of untrusted data
6.1CVSS 3.1 base score, v2 4.3
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe deserialization flaw can lead to remote code execution, public exploit references exist, and EPSS is near the top of the distribution, even though the CVSS base score is only 6.1 and the CVE is not in KEV.

What it is

Apache OFBiz 17.12.03 exposes XML-RPC endpoints that perform unsafe deserialization of untrusted data and are also vulnerable to cross-site scripting. The deserialization flaw is the serious part: it allows crafted XML-RPC requests to reach Java object deserialization, which is a well-known path to remote code execution. The XSS issue is secondary and requires a victim to interact with a crafted request.

Impact

An attacker who can reach the XML-RPC endpoint can trigger deserialization of attacker-controlled data, potentially leading to remote command execution on the OFBiz server. The XSS component can execute script in a victim's browser session, but the deserialization path is the higher-impact outcome.

Attack surface

Reached over the network via XML-RPC requests to the OFBiz web application; the CVSS vector shows no privileges required (PR:N) but user interaction required (UI:R), which fits the XSS component more than the deserialization path. The deserialization issue itself is network-reachable and does not inherently require authentication based on the record.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.98926, 99.9th percentile) and multiple references are tagged Exploit, including Packet Storm entries for Java deserialization and remote command execution. Public exploit material exists, so exploitation should be treated as practical rather than theoretical.

What to do

  • Upgrade Apache OFBiz to a fixed release; the record names 17.12.03 as vulnerable, so apply the vendor's patched version.
  • If immediate upgrade is not possible, restrict network access to OFBiz XML-RPC endpoints to trusted hosts only.
  • Disable or block XML-RPC functionality that is not required for business operations.
  • Apply input validation and deserialization filtering on any remaining XML-RPC handlers, and review Java deserialization gadget exposure on the host.
  • Monitor Apache OFBiz security mailing list and vendor advisories for the exact fixed version and any follow-up patches.

Detection

  • Inspect web and application logs for XML-RPC POST requests to OFBiz endpoints, especially those with unusual or serialized Java payloads.
  • Alert on outbound network connections or process creation from the OFBiz server that are not part of normal application behavior, which may indicate post-exploitation.
  • Monitor for known Java deserialization gadget signatures in HTTP request bodies reaching OFBiz.
  • Review OFBiz access logs for anomalous client IPs or request patterns targeting XML-RPC paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/158887/Apache-OFBiz-XML-RPC-Java-Deserialization.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/161769/Apache-OFBiz-XML-RPC-Java-Deserialization.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/163730/Apache-OfBiz-17.12.01-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
https://lists.apache.org/thread.html/r0a0a701610b3bcdf14634047313adab3f1628bb9aa55cf29cd262ef5%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r8fb319dc1f196563955fbf5e9cf454fb9d6c27c2058066445af7f8cb%40%3Cuser.ofbiz.apache.or
https://lists.apache.org/thread.html/ra43cfe80226c3b23cd775f3543da10c035ad9c9943cfe8a680490730%40%3Cuser.ofbiz.apache.or
https://lists.apache.org/thread.html/raf6020f765f12711e817ce13df63ecd7d677eebea8001e0473ee7c84%40%3Cannounce.apache.org%
https://lists.apache.org/thread.html/rde93e1c91620335b72b798f78ab4459d3f7b06f96031d8ce86a18825%40%3Cnotifications.ofbiz.
https://s.apache.org/l0994 Mailing ListVendor Advisory
http://packetstormsecurity.com/files/158887/Apache-OFBiz-XML-RPC-Java-Deserialization.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/161769/Apache-OFBiz-XML-RPC-Java-Deserialization.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/163730/Apache-OfBiz-17.12.01-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
https://lists.apache.org/thread.html/r0a0a701610b3bcdf14634047313adab3f1628bb9aa55cf29cd262ef5%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r8fb319dc1f196563955fbf5e9cf454fb9d6c27c2058066445af7f8cb%40%3Cuser.ofbiz.apache.or
https://lists.apache.org/thread.html/ra43cfe80226c3b23cd775f3543da10c035ad9c9943cfe8a680490730%40%3Cuser.ofbiz.apache.or
https://lists.apache.org/thread.html/raf6020f765f12711e817ce13df63ecd7d677eebea8001e0473ee7c84%40%3Cannounce.apache.org%
https://lists.apache.org/thread.html/rde93e1c91620335b72b798f78ab4459d3f7b06f96031d8ce86a18825%40%3Cnotifications.ofbiz.
https://s.apache.org/l0994 Mailing ListVendor Advisory

Track CVE-2020-9496 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2020-9496), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.