← Vulnerability feed

Vulnerability record · CVE-2024-45195 · published 4 September 2024

CVE-2024-45195: Apache OFBiz forced browsing exposes restricted endpoints

Apache · Ofbiz

Apache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functionality that should require authentication or authorization. Because OFBiz is a widely deployed ERP and e-commerce platform, unauthenticated access to protected endpoints can expose sensitive data and administrative functions.

7.5 CVSS 3.1 High CISA KEV since 4 Feb 2025 EPSS 100% · top 0.1% CWE-425 · CWE-425
7.5CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityThe flaw is remotely exploitable without authentication, is listed in CISA KEV as actively exploited, and has an EPSS probability near 1.0.

What it is

Apache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functionality that should require authentication or authorization. Because OFBiz is a widely deployed ERP and e-commerce platform, unauthenticated access to protected endpoints can expose sensitive data and administrative functions.

Impact

An attacker gains access to protected resources and functionality without authenticating, with high confidentiality impact per the CVSS vector. The record does not state whether integrity or availability can also be affected.

Attack surface

Reachable over the network via HTTP requests to the OFBiz web application, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not identify the specific URL paths or endpoints involved.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-04, indicating active exploitation, and EPSS gives a 30-day probability of 0.99983 (99.98th percentile). No ransomware campaign use is documented in the record.

What to do

  • Upgrade Apache OFBiz to version 18.12.16 or later, which the vendor states fixes the issue.
  • If immediate upgrade is not possible, follow the vendor guidance in the Apache security advisory and CISA required action, or discontinue use of the product.
  • Restrict network access to OFBiz web interfaces so only trusted networks or users can reach them.
  • Review and enforce authorization checks on OFBiz endpoints, especially any reachable without authentication.
  • Monitor for exploitation attempts against internet-exposed OFBiz instances until patched.

Detection

  • Review OFBiz access logs for direct requests to protected or administrative paths that return success without a prior authentication event.
  • Alert on requests to OFBiz endpoints from unauthenticated sessions that would normally require login.
  • Correlate OFBiz web logs with CISA KEV timelines and known scanning activity against the product.
  • Audit exposed OFBiz instances for version below 18.12.16.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-45195 to the Known Exploited Vulnerabilities catalog on 4 February 2025 as "Apache OFBiz Forced Browsing Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 February 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45195 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%9.8CVE-2024-45507Apache OFBiz SSRF and code injection before 18.12.16Apache OFBiz before 18.12.16 is affected by a server-side request forgery flaw combined with improper control of code generation (code injection). Th…EPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2024-45195), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.