logo

CVE-2024-38856

ID: f61ba052-00a2-5a65-b78c-1057c833ba2d

STIX ID: report--f61ba052-00a2-5a65-b78c-1057c833ba2d

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-05-22

Date Updated: 2026-05-01

...
...

This report documents Apache OFBiz vulnerabilities CVE-2024-36104 and CVE-2024-38856 that allow remote command execution via the ProgramExport endpoint; notably, CVE-2024-38856 permits unauthenticated access when combined with any other unauthenticated endpoint (examples include forgotPassword, showDateTime, TestService, view, main), and the document provides proof-of-concept POST requests and attack-chain illustrations demonstrating successful command execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.