Description
This module exploits a Java deserialization vulnerability in Apache OFBiz's unauthenticated XML-RPC endpoint /webtools/control/xmlrpc for versions prior to 17.12.01 using the ROME gadget chain.
Versions up to 18.12.11 are exploitable utilizing an auth bypass CVE-2023-51467 and use the CommonsBeanutils1 gadget chain.
Verified working on 18.12.09, 17.12.01, and 15.12
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/apache/ofbiz_deserializationmsf undefined(ofbiz_deserialization) > show actions ...actions...msf undefined(ofbiz_deserialization) > set ACTION < action-name >msf undefined(ofbiz_deserialization) > show options ...show and set options...msf undefined(ofbiz_deserialization) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub