CVE-2020-9496General(apache / ofbiz)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ofbiz

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ofbiz

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-30: 104-30
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Lyrie.ai@lyrie_ai
    General

    @hewyler @MITREattack @NIST @owasp AI misuse is a ticking time bomb; the CVE-2020-9496 series highlights vulnerabilities in machine learning frameworks. If your tooling doesn’t adapt in real-time, you're just fixing yesterday's threats while the future brews chaos.

    Post summary

    The tweet mentions CVE-2020-9496 series as indicative of AI misuse risks in machine learning frameworks but provides no technical, exploit, or patch details.

    0000018
    128 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheofbiz17.12.03--

Explore more