Vulnerability record · CVE-2024-38856 · published 5 August 2024
CVE-2024-38856: Apache OFBiz incorrect authorization allows unauthenticated code execution
Apache · Ofbiz
Apache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if preconditions are met, such as screen definitions relying on endpoint configuration instead of explicit permission checks. It matters because the flaw is remotely reachable without credentials and is listed in CISA KEV, so it is being exploited in the wild.
Description
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network exploitation, KEV listing and near-maximum EPSS probability make this an urgent patch-first issue.
What it is
Apache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if preconditions are met, such as screen definitions relying on endpoint configuration instead of explicit permission checks. It matters because the flaw is remotely reachable without credentials and is listed in CISA KEV, so it is being exploited in the wild.
Impact
An unauthenticated attacker can execute screen rendering code on the server, which can lead to full compromise of confidentiality, integrity and availability. CVSS 3.1 scores it 9.8 with high impact across all three categories.
Attack surface
Reachable over the network via unauthenticated endpoints; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. Exploitation depends on preconditions such as screen definitions that do not explicitly check permissions.
Exploitation
CISA added it to KEV on 2024-08-27 with a 2024-09-17 remediation due date, and EPSS gives a 30-day probability of 0.99427 (99.94th percentile). No ransomware campaign use is documented in the record.
What to do
- Upgrade Apache OFBiz to 18.12.15 or later, which the vendor states fixes the issue.
- If immediate upgrade is not possible, restrict network access to OFBiz endpoints to trusted sources and follow vendor mitigation guidance.
- Review screen definitions and endpoint configurations for missing explicit permission checks.
- Monitor the Apache OFBiz security page and mailing list for further vendor guidance.
- Treat internet-exposed OFBiz instances as compromised until triaged, given KEV listing and active exploitation.
Detection
- Hunt for unexpected requests to unauthenticated OFBiz endpoints, especially those that trigger screen rendering, in web access logs.
- Look for anomalous process execution or child processes spawned by the OFBiz Java process.
- Alert on outbound connections from OFBiz hosts to unfamiliar destinations, which may indicate post-exploitation activity.
- Correlate OFBiz access logs with file writes or new files in web-accessible directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-38856 to the Known Exploited Vulnerabilities catalog on 27 August 2024 as "Apache OFBiz Incorrect Authorization Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 17 September 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://issues.apache.org/jira/browse/OFBIZ-13128 | Issue Tracking |
| https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w | Mailing ListVendor Advisory |
| https://ofbiz.apache.org/download.html | Product |
| https://ofbiz.apache.org/security.html | Patch |
| http://www.openwall.com/lists/oss-security/2024/08/04/1 | Mailing List |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38856 | Third Party AdvisoryUS Government Resource |
Track CVE-2024-38856 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-38856), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.