logo

Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack

ID: 5cbfb18d-b923-5fe3-b676-d305efeb4392

STIX ID: report--5cbfb18d-b923-5fe3-b676-d305efeb4392

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2023-12-27

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

A newly discovered zero-day (CVE-2023-51467) in Apache OFBiz allows attackers to bypass authentication — due to an incomplete patch for CVE-2023-49070 — by exploiting the requirePasswordChange parameter, enabling SSRF and unauthorized access; SonicWall and Shadowserver report large numbers of exploitation attempts and users are urged to update to version 18.12.11 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.