New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-51467 | The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code NVD description · AI analysis pending | 9.8 | 96% |
| — | ||
| CVE-2024-32113 | Critical Unauthenticated Path Traversal in Apache OFBiz Apache OFBiz before 18.12.13 contains a path traversal vulnerability (CWE-22) in which improper limitation of a pathname allows access to restricted directories outside the intended scope. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw can be triggered remotely by an unauthenticated attacker with no user interaction. Successful exploitation has high impact on confidentiality, integrity, and availability: an attacker can reach files and directories that should be restricted, and the critical 9.8 score indicates potential full compromise of the affected server. Any organization running an affected version of the open-source Apache OFBiz ERP/enterprise automation suite is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS assigns a 99.4% probability of exploitation within 30 days (100th percentile), amid a wave of critical OFBiz flaws patched in 2024. Do: Upgrade all Apache OFBiz instances to version 18.12.13 or later immediately, per the vendor fix and CISA KEV required action. Because the flaw is under active exploitation, prioritize any OFBiz servers exposed to the internet, hunt for signs of compromise on unpatched systems, and restrict network access to OFBiz until patched. | 9.8 | 99% | KEV |
| moderateseveral thousand internet-exposed OFBiz instances (estimate, on the order of 10^3) | |
| CVE-2024-36104 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue. NVD description · AI analysis pending | 9.1 | 88% |
| — | ||
| CVE-2024-38856 | Pre-auth RCE via Incorrect Authorization in Apache OFBiz CVE-2024-38856 is an incorrect authorization flaw (CWE-863) in Apache OFBiz, an open-source ERP and e-commerce platform, affecting all versions through 18.12.14. On deployments where screen definitions do not explicitly verify a user's permissions because they rely on the configuration of the endpoints serving them, unauthenticated endpoints can be made to execute the screens' rendering code. As coverage of the fix describes, this can be leveraged for unauthenticated (pre-auth) remote code execution on the OFBiz server, consistent with the critical 9.8 CVSS score. Any organization running Apache OFBiz 18.12.14 or earlier, especially with the OFBiz web interface exposed to the internet, is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-08-27 amid active exploitation reports, and EPSS estimates a 99.4% probability of exploitation within 30 days. Do: Upgrade all Apache OFBiz servers to version 18.12.15 or later immediately; the KEV listing requires applying vendor mitigations or discontinuing use within the required deadline, and newer OFBiz releases also address additional 2024 flaws (e.g., CVE-2024-45195), so updating to the latest available version is prudent. Inventory internet-facing OFBiz deployments and restrict unauthenticated access to OFBiz web endpoints where possible. Hunt for signs of exploitation (unexpected screen/view rendering requests to unauthenticated endpoints and follow-on activity on OFBiz hosts), since the flaw is being actively exploited. | 9.8 | 99% | KEV |
| moderate~several thousand internet-exposed Apache OFBiz instances |
Full article335 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 06, 2024Enterprise Security / Vulnerability
A new zero-day pre-authentication remote code execution vulnerability has been disclosed in the Apache OFBiz open-source enterprise resource planning (ERP) system that could allow threat actors to achieve remote code execution on affected instances.
Tracked as CVE-2024-38856, the flaw has a CVSS score of 9.8 out of a maximum of 10.0. It affects Apache OFBiz versions prior to 18.12.15.
"The root cause of the vulnerability lies in a flaw in the authentication mechanism," SonicWall, which discovered and reported the shortcoming, said in a statement.
"This flaw allows an unauthenticated user to access functionalities that generally require the user to be logged in, paving the way for remote code execution."
CVE-2024-38856 is also a patch bypass for CVE-2024-36104, a path traversal vulnerability that was addressed in early June with the release of 18.12.14.
SonicWall described the flaw as residing in the override view functionality that exposes critical endpoints to unauthenticated threat actors, who could leverage it to achieve remote code execution via specially crafted requests.
"Unauthenticated access was allowed to the ProgramExport endpoint by chaining it with any other endpoints that do not require authentication by abusing the override view functionality," security researcher Hasib Vhora said.
The development comes as another critical path traversal vulnerability in OFBiz that could result in remote code execution (CVE-2024-32113) has since come under active exploitation to deploy the Mirai botnet. It was patched in May 2024.
In December 2023, SonicWall also disclosed a then-zero-day flaw in the same software (CVE-2023-51467) that made it possible to bypass authentication protections. It was subsequently subjected to a large number of exploitation attempts.
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 7, 2024, added CVE-2024-32113 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by August 28, 2024.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/08/new-zero-day-flaw-in-apache-ofbiz-erp.html