Vulnerability record · CVE-2021-30128 · published 27 April 2021
CVE-2021-30128: Apache OFBiz unsafe deserialization enables remote code execution
Apache · Ofbiz
Apache OFBiz contains unsafe deserialization of untrusted data prior to version 17.12.07, tracked as CWE-502. Because the flaw is network-reachable with no authentication or user interaction, it exposes OFBiz deployments to remote code execution. The record does not specify which endpoint or component performs the deserialization.
Description
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS probability, makes this an urgent remote code execution risk.
What it is
Apache OFBiz contains unsafe deserialization of untrusted data prior to version 17.12.07, tracked as CWE-502. Because the flaw is network-reachable with no authentication or user interaction, it exposes OFBiz deployments to remote code execution. The record does not specify which endpoint or component performs the deserialization.
Impact
An unauthenticated attacker can execute arbitrary code in the context of the OFBiz server, leading to full compromise of confidentiality, integrity and availability. This can result in data theft, application takeover and use of the host as a foothold into connected systems.
Attack surface
The CVSS vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no privileges and no user interaction required. The description does not identify the specific request path or interface that accepts the serialized data.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.812 (99.6th percentile), indicating strong likelihood of exploitation activity. Reference tags include Patch and Vendor Advisory but no public exploit tag, so weaponized exploit code is not confirmed by this record.
What to do
- Upgrade Apache OFBiz to 17.12.07 or later, which the advisory references as the fixed release.
- If immediate upgrade is not possible, restrict network access to OFBiz management and application endpoints to trusted hosts only.
- Apply the vendor mitigation guidance referenced in the Apache mailing list advisory.
- Monitor for and block deserialization payloads at the web tier or WAF where feasible.
- Review OFBiz deployments for exposure to the internet and remove unnecessary external access.
Detection
- Monitor OFBiz application and web server logs for unexpected deserialization errors or Java class-loading exceptions.
- Alert on suspicious child processes spawned by the OFBiz Java process, such as shells or scripting interpreters.
- Inspect network traffic to OFBiz endpoints for serialized Java object payloads (for example, streams beginning with the Java serialization magic bytes).
- Baseline normal OFBiz outbound connections and flag new external callbacks from the server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-30128 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.