216.73.216.6

Increased Activity Against Apache OFBiz CVE-2024-32113

· Published 01/08/2024 09:01 · Modified 01/08/2024 09:30

Export JSON

Essential information

Published
01/08/2024 09:01
Modified
01/08/2024 09:30
Tags
2024-08-01 CVE-2024-32113 apache erp ofbiz remote code execution vulnerability
Related entities
1 vulnerabilities (cve), 5 observables, 3 techniques (mitre)

Description

Recently, there has been a surge in malicious activity targeting a critical () in the framework, a Java-based platform for developing Enterprise Resource Planning () applications. This , a path traversal issue that can lead to , affects versions prior to 18.12.13. Attackers have been exploiting the by inserting a semicolon and accessing restricted URLs, allowing them to execute arbitrary code on vulnerable systems. Observed exploitation attempts involve hosting malicious scripts and attempting to download and execute them on compromised servers. While the vulnerable population is relatively small, threat actors are actively scanning for and exploiting this .

External references