Due to vulnerabilities in Log4j library used by Apache OFBiz, an unauthenticated attacker can leak sensitive information or execute arbitrary code on the system.
An unauthenticated attacker can take control over Apache OFBiz server
Upgrade to the latest version of Apache OFBiz

You can search and find all vulnerabilities
