Apache基金會修補ERP系統OFBiz重大風險漏洞
支付動態 · 2024-09-10

資安業者Rapid7公布上週修補的ERP系統OFBiz漏洞CVE-2024-45195,並指出該漏洞能夠被用來繞過今年Apache基金會修補的3項弱點

9月4日Apache基金會發布ERP系統OFBiz新版18.12.16,當中修補重大層級漏洞CVE-2024-45195(CVSS風險評分為9.8),通報此事的研究人員近日公布相關細節。

資安業者Rapid7指出,透過這項漏洞,未經授權的攻擊者能夠從遠端連至Windows或Linux電腦執行任意程式碼,原因是網頁應用程式缺乏檢視授權查核機制造成。

研究人員特別提及,這項漏洞與Apache基金會先前修補的CVE-2024-32113、CVE-2024-36104、CVE-2024-38856(CVSS風險評分為9.1至9.8),發生的根本原因相同,都是控制器與檢視圖解失去同步能力造成,而能讓攻擊者有機會在未通過身分驗證的情況下,執行SQL查詢或是特定程式碼,從而達到遠端執行程式碼攻擊的目的。

值得留意的是,上述漏洞已有部分出現實際攻擊行動。其中在今年5月公布的CVE-2024-32113,8月美國網路安全暨基礎設施安全局(CISA)加入已被利用的漏洞名冊(KEV),SANS網路風暴中心研究人員指出,攻擊者將其用來散布殭屍網路病毒OFBiz,因此,很有可能接下來也會有駭客嘗試利用CVE-2024-45195。

由於CVE-2024-45195能夠繞過Apache基金會針對CVE-2024-32113、CVE-2024-36104、CVE-2024-38856修補的程式碼,IT人員若不處理,潛藏的危險有可能會超過這些漏洞。

Popular articles
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
New Jersey July Gambling Revenue Hits $606M, Sweeps Casinos Banned
Regulation
Indiana online casino bill stalls in House committee
Regulation
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
British gambling levy rates confirmed for each vertical
Regulation
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
Home
Game
Cooperation
Find
My