HomeUpdatesApache fixes critical vulnerability in OFBiz

Apache fixes critical vulnerability in OFBiz

Apache has fixed a critical vulnerability in its OFBiz (Open For Business) software , which allows attackers to execute code on vulnerable servers Linux and Windows .

Apache OFBiz vulnerability

OFBiz is a popular suite of customer relationship management (CRM) and enterprise resource planning (ERP) business applications

The vulnerability found in Apache OFBiz is tracked as CVE-2024-45195 and was discovered by security researchers at Rapid7.

See also: Cisco patches critical vulnerability in Cisco ISE

In a report that includes a proof of concept (PoC) exploit, security researcher Ryan Emmons explained how an attacker, without valid credentials, can exploit the vulnerability to execute code on a server.

The Apache security team has patched the vulnerability in OFBiz version 18.12.16, adding authorization checks. OFBiz users are urged to upgrade their installations as soon as possible.

See also: Google: Update released for Pixels to eliminate vulnerability

Researcher Emmons also said that CVE-2024-45195 is a bypass patch for three other OFBiz vulnerabilities , CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856 , that have been patched by the company over the year.

"Based on our analysis, the vulnerabilities are essentially the same vulnerability with the same root cause," Emmons added.

Apache fixes critical vulnerability in OFBiz

All of this is caused by a “controller-view map fragmentation” issue, which allows attackers to execute code or SQL queries and achieve remote code execution without authentication.

See also: D-Link: Will not fix new vulnerabilities in DIR-846W router

The recent security update released by Apache for OFBiz serves as a reminder of the importance of regularly updating and securing software open source. By staying vigilant and implementing recommended security practices, organizations can protect their environment from potential threats. It is crucial to address security concerns proactively rather than “reactively.” Applying updates, released by software vendors, is essential to maintaining a secure system. Therefore, always stay up-to-date and follow security best practices to protect your business from potential vulnerabilities.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS