Apache has fixed a critical vulnerability in its OFBiz (Open For Business) software , which allows attackers to execute code on vulnerable servers Linux and Windows .

OFBiz is a popular suite of customer relationship management (CRM) and enterprise resource planning (ERP) business applications
The vulnerability found in Apache OFBiz is tracked as CVE-2024-45195 and was discovered by security researchers at Rapid7.
See also: Cisco patches critical vulnerability in Cisco ISE
In a report that includes a proof of concept (PoC) exploit, security researcher Ryan Emmons explained how an attacker, without valid credentials, can exploit the vulnerability to execute code on a server.
The Apache security team has patched the vulnerability in OFBiz version 18.12.16, adding authorization checks. OFBiz users are urged to upgrade their installations as soon as possible.
See also: Google: Update released for Pixels to eliminate vulnerability
Researcher Emmons also said that CVE-2024-45195 is a bypass patch for three other OFBiz vulnerabilities , CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856 , that have been patched by the company over the year.
"Based on our analysis, the vulnerabilities are essentially the same vulnerability with the same root cause," Emmons added.

All of this is caused by a “controller-view map fragmentation” issue, which allows attackers to execute code or SQL queries and achieve remote code execution without authentication.
See also: D-Link: Will not fix new vulnerabilities in DIR-846W router
The recent security update released by Apache for OFBiz serves as a reminder of the importance of regularly updating and securing software open source. By staying vigilant and implementing recommended security practices, organizations can protect their environment from potential threats. It is crucial to address security concerns proactively rather than “reactively.” Applying updates, released by software vendors, is essential to maintaining a secure system. Therefore, always stay up-to-date and follow security best practices to protect your business from potential vulnerabilities.
Source: www.bleepingcomputer.com
