Tag: enterprise resource planning

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution
News

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution

The open-source enterprise resource planning (ERP) system Apache OFBiz has a newly discovered security vulnerability that, if successfully exploited, might result in unauthenticated remote code execution on Windows and Linux. This high-severity vulnerability impacts all software versions prior to 18.12.16 and is tracked as CVE-2024-45195 (CVSS score: 7.5). In a recent article, Rapid7 security researcher Ryan Emmons stated that an attacker without legitimate credentials might execute arbitrary code on the server by taking advantage of the web application's lack of view authorization checks. Note that CVE-2024-45195 is a workaround for a series of problems that the project maintainers have been addressing over the last few months read more about Apache OFBiz Update Fixes High-Sever...
New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution
News

New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution

The open-source enterprise resource planning (ERP) system Apache OFBiz has a newly discovered zero-day pre-authentication remote code execution vulnerability that could grant threat actors remote code execution on vulnerable installations. The vulnerability, tracked as CVE-2024-38856, has a 9.8 out of a possible 10.0 CVSS score. Versions of Apache OFBiz lower than 18.12.15 are impacted. A statement from SonicWall, the company that found and reported the issue, stated that the authentication mechanism's fault is the main source of the problem. This vulnerability opens the door for remote code execution by enabling an unauthorized user to access features that usually need login credentials read more about New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution. Get up...