Apache OFBiz SOAP Java Deserialization
Posted by deepcore on April 7, 2021 – 8:32 pm
This Metasploit module exploits a Java deserialization vulnerability in Apache OFBiz’s unauthenticated SOAP endpoint /webtools/control/SOAPService for versions prior to 17.12.06.
Post a reply
You must be logged in to post a comment.