← Vulnerability feed

Vulnerability record · CVE-2024-32113 · published 8 May 2024

CVE-2024-32113: Apache OFBiz path traversal allows unauthenticated remote compromise

Apache · Ofbiz

Apache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is reachable over the network without authentication, it exposes the application to full compromise of confidentiality, integrity and availability.

9.8 CVSS 3.1 Critical CISA KEV since 7 Aug 2024 EPSS 100% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References
17 Jun 2026Last modified by NVD

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network path traversal, KEV-listed with a 99.9th percentile EPSS score, and a vendor patch available make this an urgent patch-first item.

What it is

Apache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is reachable over the network without authentication, it exposes the application to full compromise of confidentiality, integrity and availability.

Impact

An unauthenticated attacker can traverse outside the intended directory, potentially reading or writing files and executing code in the context of the OFBiz server, leading to full system compromise.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify the exact endpoint or parameter involved.

Exploitation

CVE-2024-32113 is listed in CISA KEV (added 2024-08-07) and has an EPSS 30-day probability of 0.99442 (99.9th percentile), indicating active exploitation and very high likelihood of attempts. No ransomware campaign use is documented in the record.

What to do

  • Upgrade Apache OFBiz to version 18.12.13 or later, which the vendor states fixes the issue.
  • If immediate upgrade is not possible, apply the vendor mitigations referenced in the Apache security page or discontinue use of the product, per CISA KEV guidance.
  • Restrict network access to OFBiz instances so they are not exposed to untrusted networks.
  • Monitor for and block path traversal patterns (../, encoded variants) in requests to OFBiz endpoints.
  • Verify no unauthorized files or web shells were written to the OFBiz installation before patching.

Detection

  • Inspect web and proxy logs for path traversal sequences such as ../ and encoded equivalents in requests to OFBiz URLs.
  • Alert on unexpected file creation or modification within the OFBiz webroot and application directories.
  • Monitor for anomalous outbound connections or process execution from the OFBiz server following suspicious HTTP requests.
  • Correlate requests to OFBiz endpoints with file system audit events to identify traversal-driven reads or writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-32113 to the Known Exploited Vulnerabilities catalog on 7 August 2024 as "Apache OFBiz Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-32113 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%9.8CVE-2024-45507Apache OFBiz SSRF and code injection before 18.12.16Apache OFBiz before 18.12.16 is affected by a server-side request forgery flaw combined with improper control of code generation (code injection). Th…EPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2024-32113), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.