"value":"The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream` instance is slightly guarded by disabling the creation of `ProcessBuilder`. However, this can be easily bypassed (and in multiple ways). Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16 r1850017+1850019"
},
{
"lang":"es",
"value":"El motor HTTP de Apache OFBiz (org.apache.ofbiz.service.engine.HttpEngine.java) maneja las peticiones de servicios HTTP por medio del end point /webtools/control/httpService. Este servicio toma el par\u00e1metro \"serviceContent\" en la petici\u00f3n y lo deserializa usando XStream. Esta instancia de \"XStream\" est\u00e1 ligeramente protegida al deshabilitar la creaci\u00f3n de \"ProcessBuilder\". Sin embargo, esto puede ser omitido f\u00e1cilmente (y de m\u00faltiples maneras). Mitigaci\u00f3n: actualice a la versi\u00f3n 16.11.06 o aplique manualmente las siguientes confirmaciones en la derivaci\u00f3n 16 r1850017+1850019."