Critical - CVSS 9.1
Added 2/4/2025

Apache OFBiz Forced Browsing Vulnerability

CVE-2024-45195
Action was due by: 2/25/2025
CISA Known Exploited Vulnerability

This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

Overview

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

Vendor

Apache

Product

OFBiz

Category

Software
Technical Details

Affected Versions

See vendor advisory

Technical Description

This vulnerability was identified in OFBiz by Apache. Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

Exploitability

Medium - Publicly disclosed

Impact

Complete system compromise possible

Additional Notes

This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://ofbiz.apache.org/security.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-45195

Required Action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 2/25/2025