CVE-2019-0189 Details
Description
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache ofbiz | >= 16.11.01, < 16.11.06 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| May 2, 2020 | CVE Modified | [email protected] |
| Apr 30, 2020 | CVE Modified | [email protected] |
| Mar 6, 2020 | CVE Modified | [email protected] |
| Feb 26, 2020 | CVE Modified | [email protected] |
| Feb 24, 2020 | CVE Modified | [email protected] |
| Feb 24, 2020 | CVE Modified | [email protected] |
| Feb 24, 2020 | CVE Modified | [email protected] |
| Feb 6, 2020 | CVE Modified | [email protected] |
| Sep 13, 2019 | Initial Analysis | [email protected] |
| Sep 13, 2019 | CVE Modified | [email protected] |