CISA warnt vor aktiv ausgenutzter Apache OFBiz RCE-Schwachstelle

Teilen:

The U.S. Cybersecurity & Infrastructure Security Agency is warning of two vulnerabilities exploited in attacks, including a path traversal impacting Apache OFBiz.

Apache OFBiz (Open For Business) is a popular open-source enterprise resource planning (ERP) system that provides a suite of business applications to manage various aspects of an organization. Due to its versatility and cost-effectiveness, it’s used in a wide range of industries and business sizes.

The flaw added to CISA’s Known Exploited Vulnerability Catalog (KEV) is CVE-2024-32113, a path traversal vulnerability impacting OFBiz versions before 18.12.13. If exploited, it could allow attackers to remotely execute arbitrary commands on vulnerable servers.

Federal agencies and state organizations are given until August 28, 2024, to apply the available security updates and mitigations that address the risk or stop using the product.

The second flaw added to KEV yesterday, and for which CISA set the same deadline, is CVE-2024-36971, an Android kernel zero-day Google fixed earlier this week.

OFBiz Flaw details

The Apache OFBiz CVE-2024-32113 flaw was addressed on May 8, 2024. By the end of the month, security researchers published complete exploitation details demonstrating how the flaw could be used for malware deployment and pivoting to other network segments.

The flaw is caused by a combination of insufficient input validation and improper handling of user-supplied data, specifically failure to sanitize URLs, which allows directory traversal sequences like ../ und ; to bypass security filters.

In addition to this, the execution of user-provided Groovy scripts has inadequate blocklisting, failing to block dangerous commands and allowing malicious actors to perform arbitrary code execution.

Soon after security researcher “Unam4” published details on exploiting the flaw on his blog, others leveraged the information to develop working exploits, which they uploaded to GitHub.

New pre-auth RCE

As CISA warns about active exploitation for CVE-2024-32113, a newer flaw that impacts more recent versions of Apache OFBiz was uncovered earlier this week.

Tracked as CVE-2024-38856, the flaw is a critical (CVSS score: 9.8) pre-authentication remote code execution problem impacting Apache OFBiz versions up to 18.12.14.

SonicWall published extensive technical details about CVE-2024-38856 on Monday, while several proof-of-concept exploits have been made available on GitHub.

Therefore, active exploitation by threat actors will likely start anytime.

This issue was fixed with the release of OFBiz version 18.12.15, which should be the upgrade target for all users of the software.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:50 pm, Juni 21, 2025
Wetter-Symbol 25°C
L: 24° | H: 26°
broken clouds
Luftfeuchtigkeit: 52 %
Druck: 1013 mb
Wind: 14 mph ESE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 59%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
24° | 26°°C 0.25 mm 25% 16 mph 64 % 1014 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 80 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 14 mph 80 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0.21 mm 21% 10 mph 85 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
16° | 20°°C 1 mm 100% 12 mph 95 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 24°°C 0.2 mm 20% 8 mph 54 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 20°°C 0.25 mm 25% 9 mph 64 % 1013 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 64 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 12 mph 49 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 14 mph 34 % 1013 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 16 mph 41 % 1012 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 14 mph 51 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 10 mph 59 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,253.76
-1.82%
Ethereum(ETH)
€1,994.35
-5.18%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.78
-3.73%
Solana(SOL)
€115.95
-4.96%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132678
-6.26%
Shiba Inu(SHIB)
€0.000010
-5.26%
Pepe(PEPE)
€0.000008
-6.87%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen