Tag: Apache OFBiz

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution
News

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution

The open-source enterprise resource planning (ERP) system Apache OFBiz has a newly discovered security vulnerability that, if successfully exploited, might result in unauthenticated remote code execution on Windows and Linux. This high-severity vulnerability impacts all software versions prior to 18.12.16 and is tracked as CVE-2024-45195 (CVSS score: 7.5). In a recent article, Rapid7 security researcher Ryan Emmons stated that an attacker without legitimate credentials might execute arbitrary code on the server by taking advantage of the web application's lack of view authorization checks. Note that CVE-2024-45195 is a workaround for a series of problems that the project maintainers have been addressing over the last few months read more about Apache OFBiz Update Fixes High-Sever...
CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports
News

CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports

Citing evidence of active exploitation in the field, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security hole affecting the open-source enterprise resource planning (ERP) system, Apache OFBiz, to its list of known exploited vulnerabilities (KEV) on Tuesday. The vulnerability, identified as CVE-2024-38856, has a critical severity CVSS score of 9.8. According to CISA, Apache OFBiz has an improper permission vulnerability that could enable remote code execution by an unauthorized attacker using a Groovy payload within the OFBiz user process. Earlier this month, SonicWall revealed details of the vulnerability, describing it as a patch bypass for another issue, CVE-2024-36104, that allows remote code execution through specially crafted request...