Executive brief
Apache OFBiz, an open-source enterprise resource planning (ERP) system used to manage business processes like inventory and accounting, is vulnerable to a code injection flaw. An attacker could potentially execute unauthorized commands or scripts within the application, leading to full system compromise or data theft. Organizations should upgrade to version 24.09.06 to protect their operations and sensitive business data.
Technical details
Apache OFBiz contains a vulnerability classified as Improper Control of Generation of Code (CWE-94) and Improper Neutralization of Directives in Dynamically Evaluated Code (CWE-95). The flaw resides in how the application handles input that is subsequently processed by a dynamic evaluation engine. An attacker can exploit this by sending specially crafted requests to inject and execute arbitrary code on the server. This typically allows for remote code execution (RCE) with the privileges of the application process. The vulnerability is resolved in version 24.09.06.
Affected products
- Apache OFBiz before 24.09.06
Timeline
- 2026-05-19: advisory: NVD and Apache Software Foundation published the advisory.
- 2026-05-19: patched: Version 24.09.06 released to address the vulnerability.