Description |
Apache OFBiz is an open-source enterprise resource planning (ERP) system that provides business solutions to various industries. It includes tools to manage business operations such as customer relationships, order processing, human resource functions, and more. According to open sources, there are hundreds of companies worldwide that use Apache OFBiz. |
Scope |
Both issues affect Apache OFBiz through 18.12.14. To date, Lacework has not observed successful exploitation of these vulnerabilities in the cloud environments we monitor. |
Solution |
It is recommended that users check for vulnerable software and subsequently upgrade to Apache OFBiz version 18.12.15. How to Find these Vulnerabilities in LaceworkSearch for these new CVEs in either the Container or Host Vulnerability pages. Example:
Detecting potential resulting exploits in run timeIf this vulnerability is exploited and the attacker conducts post-exploit actions, Lacework has a suite of detections for attacker actions. These are delivered via composite alerts, which are correlated events consisting of anomaly detection, threat intelligence, and signature based methods.
|
Additional Resources |
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.