EXECUTIVE SUMMARY:
Apache OFBiz's critical vulnerability tracked as CVE-2024-45195, a remote code execution flaw discovered by researchers. This vulnerability, present in OFBiz version before 18.12.16, affects both Linux and Windows servers by exploiting a forced browsing weakness. Attackers can bypass authorization checks to access restricted paths, leading to arbitrary code execution without valid credentials. The CVSS score for this flaw is 9.8, indicating its critical severity. Apache's patch addresses this by enforcing proper view authorization. Additionally, this vulnerability is a patch bypass for three earlier vulnerabilities—CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856—caused by controller-view map fragmentation, allowing for remote code execution and SQL injection without authentication. CVE-2024-32113, which was previously exploited in the wild, along with CVE-2024-38856, was added to CISA's catalog of actively exploited vulnerabilities, prompting a security directive for federal agencies. Organizations are strongly urged to update their systems to the latest version to mitigate potential attacks that could target their networks.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Apache OFBiz's critical vulnerability tracked as CVE-2024-45195, a remote code execution flaw discovered by researchers. This vulnerability, present in OFBiz version before 18.12.16, affects both Linux and Windows servers by exploiting a forced browsing weakness. Attackers can bypass authorization checks to access restricted paths, leading to arbitrary code execution without valid credentials. The CVSS score for this flaw is 9.8, indicating its critical severity. Apache's patch addresses this by enforcing proper view authorization. Additionally, this vulnerability is a patch bypass for three earlier vulnerabilities—CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856—caused by controller-view map fragmentation, allowing for remote code execution and SQL injection without authentication. CVE-2024-32113, which was previously exploited in the wild, along with CVE-2024-38856, was added to CISA's catalog of actively exploited vulnerabilities, prompting a security directive for federal agencies. Organizations are strongly urged to update their systems to the latest version to mitigate potential attacks that could target their networks.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]