Vulnerability record · CVE-2024-32113 · published 8 May 2024
CVE-2024-32113: Apache OFBiz path traversal allows unauthenticated remote compromise
Apache · Ofbiz
Apache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is reachable over the network without authentication, it exposes the application to full compromise of confidentiality, integrity and availability.
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network path traversal, KEV-listed with a 99.9th percentile EPSS score, and a vendor patch available make this an urgent patch-first item.
What it is
Apache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is reachable over the network without authentication, it exposes the application to full compromise of confidentiality, integrity and availability.
Impact
An unauthenticated attacker can traverse outside the intended directory, potentially reading or writing files and executing code in the context of the OFBiz server, leading to full system compromise.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify the exact endpoint or parameter involved.
Exploitation
CVE-2024-32113 is listed in CISA KEV (added 2024-08-07) and has an EPSS 30-day probability of 0.99442 (99.9th percentile), indicating active exploitation and very high likelihood of attempts. No ransomware campaign use is documented in the record.
What to do
- Upgrade Apache OFBiz to version 18.12.13 or later, which the vendor states fixes the issue.
- If immediate upgrade is not possible, apply the vendor mitigations referenced in the Apache security page or discontinue use of the product, per CISA KEV guidance.
- Restrict network access to OFBiz instances so they are not exposed to untrusted networks.
- Monitor for and block path traversal patterns (../, encoded variants) in requests to OFBiz endpoints.
- Verify no unauthorized files or web shells were written to the OFBiz installation before patching.
Detection
- Inspect web and proxy logs for path traversal sequences such as ../ and encoded equivalents in requests to OFBiz URLs.
- Alert on unexpected file creation or modification within the OFBiz webroot and application directories.
- Monitor for anomalous outbound connections or process execution from the OFBiz server following suspicious HTTP requests.
- Correlate requests to OFBiz endpoints with file system audit events to identify traversal-driven reads or writes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-32113 to the Known Exploited Vulnerabilities catalog on 7 August 2024 as "Apache OFBiz Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/05/09/1 | Mailing List |
| https://issues.apache.org/jira/browse/OFBIZ-13006 | Vendor Advisory |
| https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd | Mailing List |
| https://ofbiz.apache.org/download.html | Product |
| https://ofbiz.apache.org/security.html | Patch |
| http://www.openwall.com/lists/oss-security/2024/05/09/1 | Mailing List |
| https://issues.apache.org/jira/browse/OFBIZ-13006 | Vendor Advisory |
| https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd | Mailing List |
| https://ofbiz.apache.org/download.html | Product |
| https://ofbiz.apache.org/security.html | Patch |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-32113 | Third Party AdvisoryUS Government Resource |
Track CVE-2024-32113 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-32113), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.