Apache OFBiz vulnerable to 'Forced Browsing' (Direct Request) attack

CVE-2024-45195
7.5HIGH

Key Information

Vendor
Apache
Status
Apache Ofbiz
Vendor
CVE Published:
4 September 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

The vulnerability CVE-2024-45195 affects Apache OFBiz versions before 18.12.16, allowing attackers to execute arbitrary code on the server without valid credentials. This vulnerability poses a severe risk to organizations relying on OFBiz, including potential data theft, disruption of operations, and lateral movement and persistence within the network. Apache has released a patch in version 18.12.16 to address this vulnerability, along with three other related vulnerabilities. Previous vulnerabilities in Apache OFBiz have been actively exploited, making it crucial for organizations to promptly implement the patch to safeguard their critical data and mitigate their attack surface.

Affected Version(s)

Apache OFBiz < 18.12.16

News Articles

EPSS Score

3% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • First article discovered by SecurityWeek

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database5 News Article(s)

Credit

shin24 from National Cyber Security Vietnam
LuanPV from National Cyber Security Vietnam
Ryan Emmons, Lead Security Researcher at Rapid7
Hasib Vhora, Senior Threat Researcher, SonicWall
Xenc from SGLAB of Legendsec at Qi'anxin Group
.