Vulnerability record · CVE-2024-25065 · published 29 February 2024
CVE-2024-25065: Apache OFBiz path traversal enables authentication bypass
Apache · Ofbiz
Apache OFBiz contains a path traversal flaw (CWE-22) that allows an attacker to bypass authentication. The vendor states the issue is fixed in version 18.12.12, and no affected version range is given in the record beyond that upgrade guidance. Because OFBiz is an enterprise resource planning platform, an authentication bypass exposes business-critical data and functions.
Description
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with network-only, unauthenticated access and high confidentiality and integrity impact, combined with a high EPSS score, makes this a top remediation priority despite no KEV listing.
What it is
Apache OFBiz contains a path traversal flaw (CWE-22) that allows an attacker to bypass authentication. The vendor states the issue is fixed in version 18.12.12, and no affected version range is given in the record beyond that upgrade guidance. Because OFBiz is an enterprise resource planning platform, an authentication bypass exposes business-critical data and functions.
Impact
An unauthenticated attacker can bypass authentication and reach functionality or data that should require a valid session. The CVSS vector rates confidentiality and integrity impact as high, so an attacker could read and modify protected application data.
Attack surface
The flaw is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so it can be triggered directly over HTTP against an exposed OFBiz instance. No authentication is needed to attempt exploitation.
Exploitation
The record does not list this CVE in CISA KEV and documents no ransomware use; EPSS is high at roughly 0.477 (98.8th percentile), indicating elevated likelihood of exploitation activity, but no public exploit reference is included in the supplied data.
What to do
- Upgrade Apache OFBiz to version 18.12.12 or later as directed by the vendor advisory.
- If immediate upgrade is not possible, restrict network access to OFBiz instances to trusted networks and place them behind an authenticating reverse proxy.
- Review OFBiz access logs for traversal-style request paths and unexpected unauthenticated access to administrative or data endpoints.
- Confirm no OFBiz instance is directly exposed to the internet and apply the vendor security guidance from ofbiz.apache.org/security.html.
Detection
- Search web and proxy logs for encoded or plain path traversal sequences (../, %2e%2e%2f) in requests to OFBiz endpoints.
- Alert on successful responses (HTTP 200) to requests that lack a valid authenticated session cookie.
- Monitor for unusual access to OFBiz administrative or data-export URLs from new source IPs.
- Correlate OFBiz application logs with WAF or IDS alerts for traversal patterns targeting the application.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/02/28/10 | Mailing List |
| https://issues.apache.org/jira/browse/OFBIZ-12887 | Issue Tracking |
| https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc | Mailing List |
| https://ofbiz.apache.org/download.html | Product |
| https://ofbiz.apache.org/release-notes-18.12.12.html | Release Notes |
| https://ofbiz.apache.org/security.html | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/02/28/10 | Mailing List |
| https://issues.apache.org/jira/browse/OFBIZ-12887 | Issue Tracking |
| https://lists.apache.org/thread/rplfjp7ppn9ro49oo7jsrpj99m113lfc | Mailing List |
| https://ofbiz.apache.org/download.html | Product |
| https://ofbiz.apache.org/release-notes-18.12.12.html | Release Notes |
| https://ofbiz.apache.org/security.html | Vendor Advisory |
Track CVE-2024-25065 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-25065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.