EXPOSURES › CVE-2024-38856
CVE-2024-38856
HIGH ⌖ ON CISA KEV · EXPLOITEDApache OFBiz allows unauthenticated remote code execution via Groovy deserialization, enabling attackers to compromise ERP systems.
Apache OFBiz contains a critical authorization flaw allowing unauthenticated attackers to execute arbitrary code via Groovy payloads, posing a severe risk to defense-industrial-base organizations relying on open-source ERP suites. This vulnerability is actively exploited in the wild and enables remote code execution without authentication, requiring immediate patching and network segmentation to prevent unauthorized access to sensitive data.
Shame score — Active exploitation of a critical RCE vulnerability in a widely-used open-source ERP suite demonstrates negligence in maintaining security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.