Threat Advisory

New Mirai Botnet Variants Target Open-Source OFBiz ERP Framework

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT, Finance & Banking, Aerospace & Aviation, Healthcare, Government & Defense, Energy & Utilities, Telecommunications, Critical Infrastructure, Retail & E-commerce, Education
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical directory traversal vulnerability, CVE-2024-32213, in the Apache OFBiz ERP framework. This flaw, affecting versions prior to 18.12.13, allows attackers to execute arbitrary code by exploiting a URL parameter without authentication. These systems can become complex and challenging to maintain, especially when customized, leading to difficulties in applying patches. The vulnerability has been targeted by exploit attempts linked to the Mirai botnet, using both URL parameters and request bodies to inject malicious commands. Despite the relatively small user base of OFBiz, the ease of exploitation has led to increased attack attempts, with observed exploit traffic coming from IPs also linked to IoT device exploitation. The attacks involve including malicious commands in URLs or POST request bodies, reflecting ongoing attempts to leverage this vulnerability for broader exploitation, potentially adding it to automated attack tools like Mirai variants.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical directory traversal vulnerability, CVE-2024-32213, in the Apache OFBiz ERP framework. This flaw, affecting versions prior to 18.12.13, allows attackers to execute arbitrary code by exploiting a URL parameter without authentication. These systems can become complex and challenging to maintain, especially when customized, leading to difficulties in applying patches. The vulnerability has been targeted by exploit attempts linked to the Mirai botnet, using both URL parameters and request bodies to inject malicious commands. Despite the relatively small user base of OFBiz, the ease of exploitation has led to increased attack attempts, with observed exploit traffic coming from IPs also linked to IoT device exploitation. The attacks involve including malicious commands in URLs or POST request bodies, reflecting ongoing attempts to leverage this vulnerability for broader exploitation, potentially adding it to automated attack tools like Mirai variants.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update Apache OFBiz product to version 18.12.13.

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/08/mirai-botnet-targeting-ofbiz-servers.html

[/emaillocker]
crossmenu