Webtools XMLRPC endpoint of Apache OFBiz uses unsafe java deserialization and it's vulnerable to deserialization attacks.An attacker could exploit this vulnerability using specially-crafted serialized data to execute arbitrary code on the system or to perform a denial of service attack.
A remote attacker can gain Remote Code Execution
Upgrade to the latest version of Apache OFBiz

You can search and find all vulnerabilities
