• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
critical zero day in apache ofbiz erp system exposes businesses to

Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack

You are here: Home / General Cyber Security News / Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack
December 27, 2023

A new zero-day security flaw has been found out in the Apache OfBiz, an open-resource Company Useful resource Setting up (ERP) procedure that could be exploited to bypass authentication protections.

The vulnerability, tracked as CVE-2023-51467, resides in the login features and is the outcome of an incomplete patch for an additional critical vulnerability (CVE-2023-49070, CVSS rating: 9.8) that was launched earlier this month.

“The security measures taken to patch CVE-2023-49070 left the root issue intact and consequently the authentication bypass was still existing,” the SonicWall Capture Labs menace analysis group, which discovered the bug, stated in a assertion shared with The Hacker News.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Apache OfBiz ERP

CVE-2023-49070 refers to a pre-authenticated remote code execution flaw impacting versions prior to 18.12.10 that, when correctly exploited, could permit risk actors to obtain comprehensive command over the server and siphon delicate details. It is prompted owing to a deprecated XML-RPC component inside of Apache OFBiz.

According to SonicWall, CVE-2023-51467 could be induced using empty and invalid USERNAME and PASSWORD parameters in an HTTP ask for to return an authentication results information, efficiently circumventing the protection and enabling a danger actor to accessibility usually unauthorized interior methods.

Cybersecurity

The attack hinges on the truth that the parameter “requirePasswordChange” is established to “Y” (i.e., yes) in the URL, triggering the authentication to be trivially bypassed irrespective of the values handed in the username and password fields.

“The vulnerability enables attackers to bypass authentication to realize a basic Server-Aspect Ask for Forgery (SSRF),” according to a description of the flaw on the NIST National Vulnerability Database (NVD).

Consumers who rely on Apache OFbiz to update to variation 18.12.11 or afterwards as quickly as feasible to mitigate any probable threats.

Observed this posting appealing? Comply with us on Twitter  and LinkedIn to study extra distinctive written content we put up.


Some pieces of this posting are sourced from:
thehackernews.com

Previous Post: «chinese hackers exploited new zero day in barracuda's esg appliances Chinese Hackers Exploited New Zero-Day in Barracuda’s ESG Appliances
Next Post: New Rugmi Malware Loader Surges with Hundreds of Daily Detections new rugmi malware loader surges with hundreds of daily detections»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.