Executive brief
Apache OFBiz, an open-source enterprise resource planning (ERP) system used to manage business processes, is vulnerable to a security flaw in how it handles directory queries. An attacker could potentially manipulate these queries to gain unauthorized access to sensitive user information or bypass authentication mechanisms. Organizations should upgrade to the latest version to prevent unauthorized data access and maintain the integrity of their business management platform.
Technical details
An LDAP injection vulnerability exists in Apache OFBiz due to improper neutralization of special elements used in LDAP queries (CWE-90). By providing specially crafted input to components that interact with an LDAP directory, a remote attacker could alter the logic of LDAP statements. This can lead to unauthorized data retrieval, privilege escalation, or authentication bypass depending on how the LDAP integration is utilized within the environment. The vulnerability is addressed in Apache OFBiz version 24.09.06.
Affected products
- Apache OFBiz before 24.09.06
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory