Rewterz
Hunters International Disguises SharpRhino RAT as Authentic Network Administrator Tool – Active IOCs
August 7, 2024
Rewterz
ICS: Delta Electronics DIAScreen Vulnerability
August 7, 2024

CVE-2024-38856 – Apache OFBiz Zero-Day Vulnerability

Severity

High

Analysis Summary

CVE-2024-38856

Apache OFBiz could allow a remote attacker to bypass security restrictions, caused by improper authorization validation. By sending a specially crafted request, an attacker could exploit this vulnerability to execute screen rendering code of screens.

Impact

  • Security Bypass

Indicators of Compromise

CVE

  • CVE-2024-38856

Affected Vendors

Apache

Affected Products

  • Apache OFBiz 18.12.14

Remediation

Upgrade to the latest version of Apache OFBiz, available from the Apache Website.

Apache Website