SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-38856

Apache OFBiz Incorrect Authorization Vulnerability

KEVCRITICAL 9.8EPSS 99.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 September 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.43% probability · 100th percentile
CISA KEV
Listed 27 August 2024 · due 17 September 2024
Weakness
CWE-863
Affected
apache/ofbiz
Source
security@apache.org

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w; https://nvd.nist.gov/vuln/detail/CVE-2024-38856

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.