S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-38856 Scanner

CVE-2024-38856 Scanner - Remote Code Execution (RCE) vulnerability in Apache OFBiz

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-38856
9.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache OFBizby Apache Software Foundation
0
ofbizby apache
0
Updated Aug 22, 2026View on NVD →
Detail

Apache OFBiz is an open-source enterprise resource planning (ERP) system that supports accounting, supply chain management, manufacturing, and more. Businesses and organizations of varied sizes utilize it to manage their business processes and data. Known for its comprehensive features, it integrates with different applications and provides a wide array of functions adaptable to multiple industries. Users prefer OFBiz due to its modularity and extensibility, given its foundation in Java, making it easier for custom development. As a widely-used platform, maintaining security is critical to protect sensitive enterprise data. Frequent updates are essential to mitigate vulnerabilities that could affect business operations.

Remote Code Execution (RCE) is a critical vulnerability that allows attackers to execute arbitrary code on a server or service without authorization. This specific RCE vulnerability in Apache OFBiz can be exploited via unauthenticated endpoints due to improper authorization checks. If certain preconditions are met, such as misconfigured endpoints, attackers can render screens and execute malicious scripts. Such vulnerabilities often lead to severe security consequences including unauthorized access and data breaches. Immediate mitigation is necessary to prevent exploitation and maintain control over sensitive information.

In this instance, the vulnerability lies within improperly secured endpoints that execute screen rendering code without adequately checking user permissions. The vulnerable parameter is located in unauthenticated POST requests to specific OFBiz endpoints, such as '/webtools/control/main/ProgramExport'. By sending specially crafted requests, attackers can execute Groovy scripts on the server, identified by the presence of specific response patterns including exception traces and system user details. The template attempts to detect this vulnerability by looking for known code execution response indicators in endpoint responses.

If successfully exploited, the Remote Code Execution vulnerability in Apache OFBiz allows attackers to gain control over the affected server. This could lead to unauthorized collection and manipulation of sensitive business data, service interruptions, and further lateral movement across interconnected systems. The business operations and reputation could be critically impacted, necessitating stringent security controls and prompt remediation to prevent such outcomes.

REFERENCES

Solution Advice
  • Upgrade Apache OFBiz to version 18.12.15 or later to address the identified vulnerability.
  • Ensure that all endpoints have correct authorization checks and configure their permissions accurately.
  • Regularly audit and review endpoint configurations for security compliance.
  • Set up monitoring to detect any unusual activities indicating potential RCE exploitation.
  • Educate developers and users on secure coding and configuration practices to prevent vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.