logo

Critical Vulnerability in Apache OFBiz Requires Immediate Patching

ID: e585a91f-63e2-5c99-ba02-0558c906fbb8

STIX ID: report--e585a91f-63e2-5c99-ba02-0558c906fbb8

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2024-08-05

Date Updated: 2026-04-22

...
...

Apache OFBiz has a critical unauthenticated RCE vulnerability (CVE-2024-38856) fixed in 18.12.15; SonicWall researchers attribute the issue to authentication flaws that allow unauthenticated access to screen-rendering code when endpoints or screen definitions do not enforce permission checks. While no confirmed exploitation of this CVE has been observed, the report warns of attacker experimentation and references recent exploitation of a separate OFBiz flaw, recommending immediate upgrades to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.