CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports
Citing evidence of active exploitation in the field, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security hole affecting the open-source enterprise resource planning (ERP) system, Apache OFBiz, to its list of known exploited vulnerabilities (KEV) on Tuesday.
The vulnerability, identified as CVE-2024-38856, has a critical severity CVSS score of 9.8.
According to CISA, Apache OFBiz has an improper permission vulnerability that could enable remote code execution by an unauthorized attacker using a Groovy payload within the OFBiz user process.
Earlier this month, SonicWall revealed details of the vulnerability, describing it as a patch bypass for another issue, CVE-2024-36104, that allows remote code execution through specially crafted request...






