logo

Apache ERP Zero-Day Underscores Dangers of Incomplete Patches

ID: a40fd28b-2938-53e3-840c-c82bdd9162f7

STIX ID: report--a40fd28b-2938-53e3-840c-c82bdd9162f7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-01-04

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

The report details active probing and exploitation of a critical Apache OFBiz zero-day (CVE-2023-51467 / OFBIZ-12873) that bypasses authentication and enables SSRF and potential RCE. Researchers observed attacks before public disclosure and found that an earlier patch failed to address all attack vectors; organizations using OFBiz (or libraries that include it) are advised to apply the updated patches, restrict access to affected endpoints, and follow security best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.