[<prev] [next>] [day] [month] [year] [list]
Message-ID: <57081781.6060209@apache.org>
Date: Fri, 8 Apr 2016 22:41:37 +0200
From: "jleroux@...che.org" <jleroux@...che.org>
To: "user@...iz.apache.org" <user@...iz.apache.org>
Cc: "dev@...iz.apache.org" <dev@...iz.apache.org>,
"security@...che.org" <security@...che.org>,
oss-security@...ts.openwall.com, bugtraq@...urityfocus.com
Subject: CVE-2016-2170: Apache OFBiz information disclosure vulnerability
==========================================
CVE-2016-2170: Apache OFBiz information disclosure vulnerability
Severity: Important
Vendor:
The Apache Software Foundation
Versions Affected:
Apache OFBiz 13.07.02 and 13.07.01
Apache OFBiz 12.04.05 and earlier releases in the series (12.04.*)
The unsupported releases 11.04.*, 10.04.* and 09.04 versions are also affected but not fixed.
Description:
The infamous Java serialization vulnerability
Mitigation:
13.07.* users should upgrade to 13.07.03
12.04.05 users should upgrade to 12.04.06 (Note though that in 12.04.06 RMI is not deactivated so you should use the recommended remediation: notsoserial)
Credit:
This infamous issue was confirmed to be an issue in OFBiz by the OFBiz team, due to two external Java libraries and RMI usage.
Remediation:
Apart when using RMI with 12.04.03 version nothing is needed. But with any version, if you use JNDI, JMX or Spring and maybe other Java classes,
please check the references (hint: use notsoserial with your own whitelist)
References:
https://cwiki.apache.org/confluence/display/OFBIZ/The+infamous+Java+serialize+vulnerability
==========================================
Powered by blists - more mailing lists