Skip to main content

Active Exploitation of Apache OFBiz Zero-day Vulnerability

A critical zero-day vulnerability in Apache OFBiz is currently under wide-spread exploitation

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A critical zero-day vulnerability in Apache OFBiz is currently under wide-spread exploitation


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Apache have released a security update addressing a critical zero-day vulnerability in Apache OFBiz.

The vulnerability referred to as CVE-2023-51467 has a CVSSv3 score of 9.8. Successful exploitation could allow an attacker to circumvent authentication processes, enabling them to remotely execute arbitrary code, meaning they can access and expose sensitive information.

Exploitation of CVE-2023-51467

SonicWall researchers have observed mass exploitation attempts of CVE-2023-51467 as a zero-day vulnerability.

Proof-of-concept exploit code is publicly available for CVE-2023-51467


Threat updates

Date Update
12 Jan 2024 Proof-of-concept code publicly available

This cyber alert has been updated to reflect this change


Remediation advice

Affected organisations are encouraged to review the Apache OFBiz Security Update and apply any relevant updates.


Definitive source of threat updates


Last edited: 12 January 2024 2:00 pm