← Vulnerability feed

Vulnerability record · CVE-2024-25065 · published 29 February 2024

CVE-2024-25065: Apache OFBiz path traversal enables authentication bypass

Apache · Ofbiz

Apache OFBiz contains a path traversal flaw (CWE-22) that allows an attacker to bypass authentication. The vendor states the issue is fixed in version 18.12.12, and no affected version range is given in the record beyond that upgrade guidance. Because OFBiz is an enterprise resource planning platform, an authentication bypass exposes business-critical data and functions.

9.1 CVSS 3.1 Critical EPSS 48% · top 1.2% CWE-22 · Path traversal
9.1CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.1 with network-only, unauthenticated access and high confidentiality and integrity impact, combined with a high EPSS score, makes this a top remediation priority despite no KEV listing.

What it is

Apache OFBiz contains a path traversal flaw (CWE-22) that allows an attacker to bypass authentication. The vendor states the issue is fixed in version 18.12.12, and no affected version range is given in the record beyond that upgrade guidance. Because OFBiz is an enterprise resource planning platform, an authentication bypass exposes business-critical data and functions.

Impact

An unauthenticated attacker can bypass authentication and reach functionality or data that should require a valid session. The CVSS vector rates confidentiality and integrity impact as high, so an attacker could read and modify protected application data.

Attack surface

The flaw is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so it can be triggered directly over HTTP against an exposed OFBiz instance. No authentication is needed to attempt exploitation.

Exploitation

The record does not list this CVE in CISA KEV and documents no ransomware use; EPSS is high at roughly 0.477 (98.8th percentile), indicating elevated likelihood of exploitation activity, but no public exploit reference is included in the supplied data.

What to do

  • Upgrade Apache OFBiz to version 18.12.12 or later as directed by the vendor advisory.
  • If immediate upgrade is not possible, restrict network access to OFBiz instances to trusted networks and place them behind an authenticating reverse proxy.
  • Review OFBiz access logs for traversal-style request paths and unexpected unauthenticated access to administrative or data endpoints.
  • Confirm no OFBiz instance is directly exposed to the internet and apply the vendor security guidance from ofbiz.apache.org/security.html.

Detection

  • Search web and proxy logs for encoded or plain path traversal sequences (../, %2e%2e%2f) in requests to OFBiz endpoints.
  • Alert on successful responses (HTTP 200) to requests that lack a valid authenticated session cookie.
  • Monitor for unusual access to OFBiz administrative or data-export URLs from new source IPs.
  • Correlate OFBiz application logs with WAF or IDS alerts for traversal patterns targeting the application.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-25065 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2024-25065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.