The popular open-source ERP software Apache OFBiz, used worldwide by numerous companies to automate business processes, is affected by a critical security vulnerability. This flaw allows attackers to compromise systems and execute their own code. The developers have already released a patched version, but the threat remains serious.
Details of the vulnerability
The security flaw, tracked as CVE-2024-38856, affects all versions of Apache OFBiz prior to the current version 18.12.15. According to the developers and security researchers, this is an authentication bypass that allows attackers to execute malicious code on affected systems without valid credentials. This makes the flaw particularly dangerous, since compromised systems must be considered completely insecure.
Exploitation possibilities and impact
A post on Seclists explains that the vulnerability stems from errors in authentication. Attackers can gain control over the system through specific manipulation of the login function. This allows not only the execution of arbitrary code, but also the potential disclosure of confidential information and further serious attacks.
SonicWall researchers additionally discovered that the vulnerability is directly linked to an incomplete patch for an earlier pre-auth RCE vulnerability (CVE-2023-49070, CVSS score: 9.8). The flaw is triggered by the special string "requirePasswordChange=Y", which allows attackers to bypass authentication. A video demonstrates how an unauthenticated attacker can execute the system application "Ping" on a vulnerable version 18.12.10.
Mitigation measures
The developers of Apache OFBiz responded quickly to the discovery and closed the security vulnerability in version 18.12.15. It is strongly recommended to update to this or a newer version to eliminate the risk. Companies should also check their systems for possible compromise and ensure that all security updates are applied promptly.
Role in the supply chain
Particularly concerning is the fact that Apache OFBiz is frequently integrated into the supply chain of well-known software solutions, including Atlassian's JIRA, which is used by over 120,000 companies worldwide. SonicWall's researchers warn that exploitation of this vulnerability could lead to significant security problems across the entire supply chain.
The security vulnerability in Apache OFBiz once again underscores the need for a proactive security strategy and regular updates. Companies should not only install the patched version 18.12.15, but also review and strengthen their security precautions. Given the far-reaching implications of this vulnerability, swift action is required to ensure the integrity and security of the systems.