Port 22

Critical RCE Vulnerability Found in Apache OFBiz ERP SoftwarePatch Now

The Apache Software Foundation on Friday addressed a high severity vulnerability in Apache OFBiz that could have allowed an unauthenticated adversary to remotely seize control of the open-source enterprise resource planning (ERP) system. Tracked asCVE-2021-26295, the flaw affects all versions of the software prior to17.12.06and employs an “unsafe deserialization” as an attack vector to permit