Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
| Software | From | Fixed in |
|---|---|---|
| apache / ofbiz | 12.04 | 12.04.06 |
| apache / ofbiz | 13.07 | 13.07.03 |