SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Apache OFBiz Java expression language injection attempt
This rule looks for attempts to invoke the "ProgramExport" endpoint to execute arbitrary Java code on Apache OFBiz web applications.
This rule fires on attempts to execution arbitrary Java code on vulnerable Apache OFBiz web servers.
Attacks/Scans seen in the wild
Known false positives, with the described conditions
This rule alerts on all attempts to execute code in the "groovyProgram" parameter via the "/ProgramExport" endpoint on Apache OFBiz web applications.
Cisco Talos Intelligence Group
No rule groups
N/A
Not Applicable
CVE-2024-38856 |
Loading description
|