By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: CISA warns about actively exploited Apache OFBiz RCE flaw
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > CISA warns about actively exploited Apache OFBiz RCE flaw
Tech News

CISA warns about actively exploited Apache OFBiz RCE flaw

By admin 3 Min Read
Share
SHARE

Contents
OFBiz Flaw detailsNew pre-auth RCE

The U.S. Cybersecurity & Infrastructure Security Agency is warning of two vulnerabilities exploited in attacks, including a path traversal impacting Apache OFBiz.

Apache OFBiz (Open For Business) is a popular open-source enterprise resource planning (ERP) system that provides a suite of business applications to manage various aspects of an organization. Due to its versatility and cost-effectiveness, it’s used in a wide range of industries and business sizes.

The flaw added to CISA’s Known Exploited Vulnerability Catalog (KEV) is CVE-2024-32113, a path traversal vulnerability impacting OFBiz versions before 18.12.13. If exploited, it could allow attackers to remotely execute arbitrary commands on vulnerable servers.

Federal agencies and state organizations are given until August 28, 2024, to apply the available security updates and mitigations that address the risk or stop using the product.

The second flaw added to KEV yesterday, and for which CISA set the same deadline, is CVE-2024-36971, an Android kernel zero-day Google fixed earlier this week.

OFBiz Flaw details

The Apache OFBiz CVE-2024-32113 flaw was addressed on May 8, 2024. By the end of the month, security researchers published complete exploitation details demonstrating how the flaw could be used for malware deployment and pivoting to other network segments.

The flaw is caused by a combination of insufficient input validation and improper handling of user-supplied data, specifically failure to sanitize URLs, which allows directory traversal sequences like ../ and ; to bypass security filters.

In addition to this, the execution of user-provided Groovy scripts has inadequate blocklisting, failing to block dangerous commands and allowing malicious actors to perform arbitrary code execution.

Soon after security researcher “Unam4” published details on exploiting the flaw on his blog, others leveraged the information to develop working exploits, which they uploaded to GitHub.

<strong>Demonstration of Apache OFBiz flaw</strong>

New pre-auth RCE

As CISA warns about active exploitation for CVE-2024-32113, a newer flaw that impacts more recent versions of Apache OFBiz was uncovered earlier this week.

Tracked as CVE-2024-38856, the flaw is a critical (CVSS score: 9.8) pre-authentication remote code execution problem impacting Apache OFBiz versions up to 18.12.14.

SonicWall published extensive technical details about CVE-2024-38856 on Monday, while several proof-of-concept exploits have been made available on GitHub.

Therefore, active exploitation by threat actors will likely start anytime.

This issue was fixed with the release of OFBiz version 18.12.15, which should be the upgrade target for all users of the software.

 

 

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: Actively Exploited, Apache, Apache OFBiz, CISA, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Malaysia's prime minister lauds country's burgeoning chip hub status as Infineon opens new plant
Next Article Computer Crash Reports Are an Untapped Hacker Gold Mine
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?