Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
The vulnerability consists of embedding a hardcoded cryptographic key directly in the Apache OFBiz application source code. Because the key is identical in all installations, a person with knowledge of it (e.g., through source code analysis or previous disclosures) can exploit it without needing to guess it. The attack vector is network-based, requires no authentication or user interaction, which significantly lowers the entry threshold for a potential attacker.
An attacker can gain unauthorized access to protected data (breach of confidentiality) and potentially modify data secured with this key (breach of integrity). According to the CVSS vector, the vulnerability does not directly affect system availability.
Apache OFBiz must be immediately updated to version 24.09.06 or newer, which eliminates the vulnerability. After updating, it is recommended to revoke and rotate the cryptographic keys and certificates that may have been compromised.
Apache OFBiz in all versions before 24.09.06
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache Ofbiz
APPApache< 24.09.06
Related vulnerabilities
Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację
Path Traversal w Apache OFBiz umożliwiający zdalne wykonanie kodu
Apache OFBiz — Auth Bypass i RCE poprzez błąd logiki zmiany hasła
LDAP Injection w Apache OFBiz umożliwiający nieautoryzowany dostęp
Apache OFBiz: Code Injection w pluginie scrum umożliwia RCE