CISA issued a warning about a security flaw in Apache OFBiz, an ERP system. The vulnerability is being actively exploited and has been added to CISA’s Known Exploited Vulnerabilities catalog as CVE-2024-38856.
CVE-2024-38856 is a serious security flaw in Apache OFBiz. It allows attackers to run code on a remote server without authentication. To stay safe, organizations should update to Apache OFBiz version 18.12.15 or newer.
By infosecbulletin
/ Friday , April 18 2025
According to Shadowserver Foundation around 17,000 Fortinet devices worldwide have been compromised using a new technique called "symlink". This number...
Read More
By infosecbulletin
/ Friday , April 18 2025
A critical security flaw has been found in the Erlang/Open Telecom Platform (OTP) SSH implementation, allowing an attacker to run...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, CISA alerted about increased breach risks due to the earlier compromise of legacy Oracle Cloud servers, emphasizing the...
Read More
By infosecbulletin
/ Thursday , April 17 2025
Cisco issued a security advisory about a serious vulnerability in its Webex App that allows unauthenticated remote code execution (RCE)...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
On April 15, 2025, Oracle released a Critical Patch Update for 378 flaws for its products. The patch update covers...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Check Point Research warns of the active exploitation of a new vulnerability, CVE-2025-24054, which lets hackers leak NTLMv2-SSP hashes using...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Bengaluru's Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a ransom of up to $70,000...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
MITRE Vice President Yosry Barsoum warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
PwC has ceased operations in more than a dozen countries that its global bosses have deemed too small, risky or...
Read More
CVE-2024-38856 is a vulnerability in Apache OFBiz’s authentication mechanism. It allows unauthorized users to access functions only meant for logged-in users. By exploiting this vulnerability, attackers can run any code on compromised systems, possibly gaining full control.
SonicWall found and reported a critical vulnerability, CVE-2024-38856, in Apache OFBiz’s override view feature. This flaw allows unauthenticated attackers to access important parts of the system by sending specific requests.
Cybersecurity researchers Zeyad Azima from SecureLayer7 and Youssef Muhammad have posted a proof-of-concept (PoC) exploit code for CVE-2024-38856 on GitHub. This makes it easier for attackers to use the vulnerability in their attacks.
CISA strongly recommends that all federal agencies and organizations using Apache OFBiz update their installations to version 18.12.15 or later by September 17, 2024. Failing to apply these updates could lead to attacks and severe consequences.