Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Critical zero-day vulnerability in Apache OfBiz ERP system leaves businesses open to attack
    Cyber Security

    Critical zero-day vulnerability in Apache OfBiz ERP system leaves businesses open to attack

    techempireBy techempireNo Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportDecember 27, 2023Editorial DepartmentZero days/vulnerabilities

    Apache OfBiz ERP

    A new zero-day security vulnerability has been discovered in Apache OfBiz, an open source enterprise resource planning (ERP) system that can be exploited to bypass authentication protection.

    The vulnerability is tracked as CVE-2023-51467resides in the login functionality, and is the result of an incomplete patch for another critical vulnerability (CVE-2023-49070, CVSS score: 9.8) released earlier this month.

    “The security measures taken to patch CVE-2023-49070 leave the underlying issue intact, so the authentication bypass remains,” the SonicWall Capture Labs threat research team, which discovered the vulnerability, said in a statement shared with The Hacker News. .”

    Apache OfBiz ERP

    CVE-2023-49070 refers to a pre-authenticated remote code execution flaw affecting versions prior to 18.12.10. Successful exploitation of the flaw could allow threat actors to take full control of the server and steal sensitive data. This is caused by the deprecated XML-RPC component in Apache OFBiz.

    According to SonicWall, CVE-2023-51467 can be triggered by using empty and invalid username and password parameters in an HTTP request to return an authentication success message, effectively circumventing protection and allowing threat actors to access unauthorized data. Authorized internal resources.

    Internet security

    This attack relies on the “requirePasswordChange” parameter in the URL being set to “Y” (i.e. “Yes”), allowing authentication to be easily bypassed regardless of the values ​​passed in the username and password fields.

    According to a description of the flaw on the NIST National Vulnerability Database (NVD), “This vulnerability allows an attacker to bypass authentication to achieve simple server-side request forgery (SSRF).”

    Users who rely on Apache OFbiz are advised to update to version 18.12.11 or higher as soon as possible to mitigate any potential threats.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.