New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution

Aug 6, 2024

A new zero-day pre-authentication remote code execution vulnerability has been disclosed in the Apache OFBiz open-source enterprise resource planning (ERP) system that could allow threat actors to achieve remote code execution on affected instances.
Tracked as CVE-2024-38856, the flaw has a CVSS score of 9.8 out of a maximum of 10.0. It affects Apache OFBiz versions prior to 18.12.15.
“The

Get Free Report & Network Analysis

Please check your email for the free report.