Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack
ID: 5cbfb18d-b923-5fe3-b676-d305efeb4392
STIX ID: report--5cbfb18d-b923-5fe3-b676-d305efeb4392
Feed Name: The Hacker News
Threat Score
A newly discovered zero-day (CVE-2023-51467) in Apache OFBiz allows attackers to bypass authentication — due to an incomplete patch for CVE-2023-49070 — by exploiting the requirePasswordChange parameter, enabling SSRF and unauthorized access; SonicWall and Shadowserver report large numbers of exploitation attempts and users are urged to update to version 18.12.11 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
