Apache behebt kritische OFBiz-Schwachstelle für entfernte Codeausführung

Teilen:

Apache has fixed a critical security vulnerability in its open-source OFBiz (Open For Business) software, which could allow attackers to execute arbitrary code on vulnerable Linux and Windows servers.

OFBiz is a suite of customer relationship management (CRM) and enterprise resource planning (ERP) business applications that can also be used as a Java-based web framework for developing web applications.

Tracked as CVE-2024-45195 and discovered by Rapid7 security researchers, this remote code execution flaw is caused by a forced browsing weakness that exposes restricted paths to unauthenticated direct request attacks.

“An attacker with no valid credentials can exploit missing view authorization checks in the web application to execute arbitrary code on the server,” security researcher Ryan Emmons explained on Thursday in a report containing proof-of-concept exploit code.

The Apache security team patched the vulnerability in version 18.12.16 by adding authorization checks. OFBiz users are advised to upgrade their installations as soon as possible to block potential attacks.

Bypass for previous security patches

As Emmons further explained today, CVE-2024-45195 is a patch bypass for three other OFBiz vulnerabilities that have been patched since the start of the year and are tracked as CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856.

“Based on our analysis, three of these vulnerabilities are, essentially, the same vulnerability with the same root cause,” Emmons added.

All of them are caused by a controller-view map fragmentation issue that enables attackers to execute code or SQL queries and achieve remote code execution without authentication.

In early August, CISA warned that the CVE-2024-32113 OFBiz vulnerability (patched in May) was being exploited in attacks, days after SonicWall researchers published technical details on the CVE-2024-38856 pre-authentication RCE bug.

CISA also added the two security bugs to its catalog of actively exploited vulnerabilities, requiring federal agencies to patch their servers within three weeks as mandated by the binding operational directive (BOD 22-01) issued in November 2021.

Even though BOD 22-01 only applies to Federal Civilian Executive Branch (FCEB) agencies, CISA urged all organizations to prioritize patching these flaws to thwart attacks that could target their networks.

In December, attackers started exploiting another OFBiz pre-authentication remote code execution vulnerability (CVE-2023-49070) using public proof of concept (PoC) exploits to find vulnerable Confluence servers.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:25 am, Juni 23, 2025
Wetter-Symbol 19°C
L: 18° | H: 21°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 47 %
Druck: 1014 mb
Wind: 16 mph W
Windböe: 27 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 27%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 21°°C 0 mm 0% 14 mph 54 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 24°°C 0 mm 0% 14 mph 80 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 10 mph 88 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 0.35 mm 35% 16 mph 81 % 1017 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
15° | 28°°C 0 mm 0% 15 mph 66 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 21°°C 0 mm 0% 12 mph 44 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 38 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 39 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 54 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 80 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 11 mph 75 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 69 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,323.22
-0.83%
Ethereum(ETH)
€1,956.87
-0.15%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.74
-1.84%
Solana(SOL)
€116.75
1.00%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132726
-1.39%
Shiba Inu(SHIB)
€0.000010
0.30%
Pepe(PEPE)
€0.000008
-1.93%
Peanut das Eichhörnchen(PNUT)
€0.218896
13.10%
Nach oben scrollen