EXECUTIVE SUMMARY:
A critical directory traversal vulnerability, CVE-2024-32213, in the Apache OFBiz ERP framework. This flaw, affecting versions prior to 18.12.13, allows attackers to execute arbitrary code by exploiting a URL parameter without authentication. These systems can become complex and challenging to maintain, especially when customized, leading to difficulties in applying patches. The vulnerability has been targeted by exploit attempts linked to the Mirai botnet, using both URL parameters and request bodies to inject malicious commands. Despite the relatively small user base of OFBiz, the ease of exploitation has led to increased attack attempts, with observed exploit traffic coming from IPs also linked to IoT device exploitation. The attacks involve including malicious commands in URLs or POST request bodies, reflecting ongoing attempts to leverage this vulnerability for broader exploitation, potentially adding it to automated attack tools like Mirai variants.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical directory traversal vulnerability, CVE-2024-32213, in the Apache OFBiz ERP framework. This flaw, affecting versions prior to 18.12.13, allows attackers to execute arbitrary code by exploiting a URL parameter without authentication. These systems can become complex and challenging to maintain, especially when customized, leading to difficulties in applying patches. The vulnerability has been targeted by exploit attempts linked to the Mirai botnet, using both URL parameters and request bodies to inject malicious commands. Despite the relatively small user base of OFBiz, the ease of exploitation has led to increased attack attempts, with observed exploit traffic coming from IPs also linked to IoT device exploitation. The attacks involve including malicious commands in URLs or POST request bodies, reflecting ongoing attempts to leverage this vulnerability for broader exploitation, potentially adding it to automated attack tools like Mirai variants.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/08/mirai-botnet-targeting-ofbiz-servers.html
[/emaillocker]