CVE-2024-45195
Apache Software Foundation Apache OFBiz, apache ofbiz
Published 4 Sept 2024 · updated 17 Jun 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 4 Feb 2025, with a remediation deadline of 25 Feb 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
References
- issues.apache.org/jira/browse/OFBIZ-13130 · Issue Tracking, Vendor Advisory
- lists.apache.org/thread/o90dd9lbk1hh3t2557t2y2qvrh92p7wy · Vendor Advisory
- ofbiz.apache.org/download.html · Product
- ofbiz.apache.org/security.html · Vendor Advisory
- www.openwall.com/lists/oss-security/2024/09/03/6 · Mailing List
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45195 · Third Party Advisory, US Government Resource