Vulnerability record · CVE-2021-29200 · published 27 April 2021
CVE-2021-29200: Apache OFBiz unsafe deserialization allows unauthenticated RCE
Apache · Ofbiz
Apache OFBiz before 17.12.07 performs unsafe deserialization of untrusted data (CWE-502), and the vendor states an unauthenticated user can achieve remote code execution. The flaw is network-reachable with no privileges or user interaction required, making it a severe pre-auth RCE risk for exposed OFBiz instances.
Description
Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication network RCE with CVSS 9.8 and very high EPSS percentile, though not yet in KEV.
What it is
Apache OFBiz before 17.12.07 performs unsafe deserialization of untrusted data (CWE-502), and the vendor states an unauthenticated user can achieve remote code execution. The flaw is network-reachable with no privileges or user interaction required, making it a severe pre-auth RCE risk for exposed OFBiz instances.
Impact
An unauthenticated attacker can execute arbitrary code on the OFBiz server, leading to full compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network via the vulnerable deserialization endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the description both indicate no authentication and no user interaction are needed.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.5537, ~99th percentile), indicating substantial predicted exploitation activity; references include patch and vendor advisory links.
What to do
- Upgrade Apache OFBiz to 17.12.07 or later, which the vendor references identify as the fixed release.
- If immediate upgrade is not possible, restrict network access to OFBiz instances to trusted networks and place them behind authentication-aware proxies.
- Monitor the OFBiz commit and announcement mailing lists referenced in the advisory for any further fixes or backports.
- Review and harden any Java deserialization entry points in custom OFBiz code and dependencies.
- Treat any internet-exposed OFBiz instance as potentially compromised and check for signs of intrusion.
Detection
- Monitor OFBiz application and web server logs for unexpected deserialization errors or unusual request payloads to OFBiz endpoints.
- Alert on outbound network connections or child processes spawned by the OFBiz Java process, which may indicate post-exploitation.
- Hunt for known Java deserialization gadget signatures (e.g., ysoserial-style payload markers) in HTTP request bodies.
- Baseline normal OFBiz request patterns and flag anomalous large or binary-encoded POST bodies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-29200 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.