CVE-2024-45195criticalunder attackCWE-425

CVE-2024-45195: critical vulnerability in Apache OFBiz

Apache OFBiz: Confused controller-view authorization logic (forced browsing)

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon322 days
Published on NVDSep 4
1st PoC+322d
CISA KEV+153d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2025-02-25

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

Apache OFBiz has a vulnerability that allows attackers to bypass authorization checks and access restricted pages directly by crafting specific requests, even without proper permissions.

Technical detail

A forced browsing vulnerability in Apache OFBiz's controller-view authorization logic (CWE-425) allows unauthenticated or unprivileged attackers to directly request restricted resources by circumventing authorization controls. The vulnerability exists in versions prior to 18.12.16 and can be exploited through direct HTTP requests to protected endpoints, resulting in unauthorized access to sensitive functionality or data.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.