Apache ERP Zero-Day Underscores Dangers of Incomplete Patches
ID: a40fd28b-2938-53e3-840c-c82bdd9162f7
STIX ID: report--a40fd28b-2938-53e3-840c-c82bdd9162f7
Feed Name: Dark Reading
Threat Score
The report details active probing and exploitation of a critical Apache OFBiz zero-day (CVE-2023-51467 / OFBIZ-12873) that bypasses authentication and enables SSRF and potential RCE. Researchers observed attacks before public disclosure and found that an earlier patch failed to address all attack vectors; organizations using OFBiz (or libraries that include it) are advised to apply the updated patches, restrict access to affected endpoints, and follow security best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
