ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Critical Vulnerability in Apache OFBiz Requires Immediate Patching

criticalVulnerability exploited in the wildimportance 60CVE-2024-38856CVE-2024-32113

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-32113
Critical Unauthenticated Path Traversal in Apache OFBiz

Apache OFBiz before 18.12.13 contains a path traversal vulnerability (CWE-22) in which improper limitation of a pathname allows access to restricted directories outside the intended scope. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw can be triggered remotely by an unauthenticated attacker with no user interaction. Successful exploitation has high impact on confidentiality, integrity, and availability: an attacker can reach files and directories that should be restricted, and the critical 9.8 score indicates potential full compromise of the affected server. Any organization running an affected version of the open-source Apache OFBiz ERP/enterprise automation suite is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS assigns a 99.4% probability of exploitation within 30 days (100th percentile), amid a wave of critical OFBiz flaws patched in 2024.

Do: Upgrade all Apache OFBiz instances to version 18.12.13 or later immediately, per the vendor fix and CISA KEV required action. Because the flaw is under active exploitation, prioritize any OFBiz servers exposed to the internet, hunt for signs of compromise on unpatched systems, and restrict network access to OFBiz until patched.

9.899% KEV
  • Apache OFBiz all versions before 18.12.13 (fixed in 18.12.13)
moderateseveral thousand internet-exposed OFBiz instances (estimate, on the order of 10^3)
CVE-2024-38856
Pre-auth RCE via Incorrect Authorization in Apache OFBiz

CVE-2024-38856 is an incorrect authorization flaw (CWE-863) in Apache OFBiz, an open-source ERP and e-commerce platform, affecting all versions through 18.12.14. On deployments where screen definitions do not explicitly verify a user's permissions because they rely on the configuration of the endpoints serving them, unauthenticated endpoints can be made to execute the screens' rendering code. As coverage of the fix describes, this can be leveraged for unauthenticated (pre-auth) remote code execution on the OFBiz server, consistent with the critical 9.8 CVSS score. Any organization running Apache OFBiz 18.12.14 or earlier, especially with the OFBiz web interface exposed to the internet, is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-08-27 amid active exploitation reports, and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Upgrade all Apache OFBiz servers to version 18.12.15 or later immediately; the KEV listing requires applying vendor mitigations or discontinuing use within the required deadline, and newer OFBiz releases also address additional 2024 flaws (e.g., CVE-2024-45195), so updating to the latest available version is prudent. Inventory internet-facing OFBiz deployments and restrict unauthenticated access to OFBiz web endpoints where possible. Hunt for signs of exploitation (unexpected screen/view rendering requests to unauthenticated endpoints and follow-on activity on OFBiz hosts), since the flaw is being actively exploited.

9.899% KEV
  • Apache OFBiz through 18.12.14 (fixed in 18.12.15)
moderate~several thousand internet-exposed Apache OFBiz instances
Full article304 words · extracted from infosecurity-magazine.com · click to collapse

Organizations utilizing Apache OFBiz have been warned to promptly address a critical vulnerability due to escalating exploitation attempts targeting a recently identified security flaw.

Tracked as CVE-2024-38856, the vulnerability was disclosed over the weekend. Apache OFBiz developers confirmed versions through 18.12.14 are impacted and included a fix in version 18.12.15.

According to an advisory published by the company on Sunday, the issue stems from unauthenticated endpoints that could allow the execution of screen-rendering code if specific preconditions are met. 

These preconditions include instances where the screen definitions do not explicitly check user permissions, relying instead on the configuration of their endpoints. This vulnerability is being tracked internally under the identifier OFBIZ-13128.

SonicWall threat researchers, who discovered the flaw, described it as a critical issue enabling unauthenticated remote code execution (RCE). They attributed the root cause to a flaw in the authentication mechanism, which allows an unauthenticated user to access functionalities meant for logged-in users, potentially leading to RCE.

At the time of writing, SonicWall has not detected any attacks exploiting CVE-2024-38856. However, another recently discovered Apache OFBiz flaw, identified in May and tracked as CVE-2024-32113, appears to have been targeted by malicious actors. 

This vulnerability, a path traversal bug, could also lead to remote command execution. The SANS Technology Institute’s Internet Storm Center reported increasing exploitation attempts of this flaw in late July.

There is evidence suggesting that attackers are experimenting with the new vulnerability, possibly integrating it into variants of the Mirai botnet. Apache OFBiz, a free framework for creating enterprise resource planning (ERP) applications, is used by several major companies, primarily in the US, India and Europe.

Read more on the Mirai botnet: Cyber Attackers Turn to Cloud Services to Deploy Malware

Users are strongly recommended to upgrade to version 18.12.15 to mitigate the newly identified threat. 

Image credit: monticello / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/fla-apache-ofbiz-requires-patching/