Re: [CVE-2020-9496] Apache OFBiz unsafe deserialization of XMLRPC arguments

2020-11-17 Thread Jacques Le Roux
Thanks for the warning Scott! Security needs to be taken seriously before damages are done. Jacques Le 16/11/2020 à 20:08, Scott Gray a écrit : Hi everyone, I was recently made aware of an attack on an OFBiz deployment using the vulnerability described below. The attackers were able to

[CVE-2020-9496] Apache OFBiz unsafe deserialization of XMLRPC arguments

2020-11-16 Thread Scott Gray
Hi everyone, I was recently made aware of an attack on an OFBiz deployment using the vulnerability described below. The attackers were able to exploit the xmlrpc endpoint to initiate a full export of the database. Fortunately this deployment had an extremely large database and the attempt set