Critical Vulnerability in Apache OFBiz Requires Immediate Patching
ID: e585a91f-63e2-5c99-ba02-0558c906fbb8
STIX ID: report--e585a91f-63e2-5c99-ba02-0558c906fbb8
Feed Name: Infosecurity Magazine (News)
Apache OFBiz has a critical unauthenticated RCE vulnerability (CVE-2024-38856) fixed in 18.12.15; SonicWall researchers attribute the issue to authentication flaws that allow unauthenticated access to screen-rendering code when endpoints or screen definitions do not enforce permission checks. While no confirmed exploitation of this CVE has been observed, the report warns of attacker experimentation and references recent exploitation of a separate OFBiz flaw, recommending immediate upgrades to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
