Tag: Apache OFBiz Update

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution
News

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution

The open-source enterprise resource planning (ERP) system Apache OFBiz has a newly discovered security vulnerability that, if successfully exploited, might result in unauthenticated remote code execution on Windows and Linux. This high-severity vulnerability impacts all software versions prior to 18.12.16 and is tracked as CVE-2024-45195 (CVSS score: 7.5). In a recent article, Rapid7 security researcher Ryan Emmons stated that an attacker without legitimate credentials might execute arbitrary code on the server by taking advantage of the web application's lack of view authorization checks. Note that CVE-2024-45195 is a workaround for a series of problems that the project maintainers have been addressing over the last few months read more about Apache OFBiz Update Fixes High-Sever...