PT-2024-5989 · Apache · Apache Ofbiz

·

CVE-2024-45195

·

Published

2024-08-14

·

Updated

2026-03-31

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 18.12.16
Description The issue is a Direct Request ('Forced Browsing') vulnerability in Apache OFBiz, which could allow attackers to execute arbitrary code on vulnerable Linux and Windows servers. This vulnerability has been actively exploited by hackers, with over 25,000 requests targeting 4,000 unique sites detected by Imperva. The vulnerability allows for unauthenticated remote code execution.
Recommendations Apache OFBiz versions prior to 18.12.16: Upgrade to version 18.12.16 to prevent attacks. As a temporary workaround, consider restricting access to vulnerable modules or functions until a patch is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06798
CVE-2024-45195

Affected Products

Apache Ofbiz