Vulnerability record · CVE-2024-45195 · published 4 September 2024
CVE-2024-45195: Apache OFBiz forced browsing exposes restricted endpoints
Apache · Ofbiz
Apache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functionality that should require authentication or authorization. Because OFBiz is a widely deployed ERP and e-commerce platform, unauthenticated access to protected endpoints can expose sensitive data and administrative functions.
Description
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, is listed in CISA KEV as actively exploited, and has an EPSS probability near 1.0.
What it is
Apache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functionality that should require authentication or authorization. Because OFBiz is a widely deployed ERP and e-commerce platform, unauthenticated access to protected endpoints can expose sensitive data and administrative functions.
Impact
An attacker gains access to protected resources and functionality without authenticating, with high confidentiality impact per the CVSS vector. The record does not state whether integrity or availability can also be affected.
Attack surface
Reachable over the network via HTTP requests to the OFBiz web application, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description does not identify the specific URL paths or endpoints involved.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-04, indicating active exploitation, and EPSS gives a 30-day probability of 0.99983 (99.98th percentile). No ransomware campaign use is documented in the record.
What to do
- Upgrade Apache OFBiz to version 18.12.16 or later, which the vendor states fixes the issue.
- If immediate upgrade is not possible, follow the vendor guidance in the Apache security advisory and CISA required action, or discontinue use of the product.
- Restrict network access to OFBiz web interfaces so only trusted networks or users can reach them.
- Review and enforce authorization checks on OFBiz endpoints, especially any reachable without authentication.
- Monitor for exploitation attempts against internet-exposed OFBiz instances until patched.
Detection
- Review OFBiz access logs for direct requests to protected or administrative paths that return success without a prior authentication event.
- Alert on requests to OFBiz endpoints from unauthenticated sessions that would normally require login.
- Correlate OFBiz web logs with CISA KEV timelines and known scanning activity against the product.
- Audit exposed OFBiz instances for version below 18.12.16.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-45195 to the Known Exploited Vulnerabilities catalog on 4 February 2025 as "Apache OFBiz Forced Browsing Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 February 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://issues.apache.org/jira/browse/OFBIZ-13130 | Issue TrackingVendor Advisory |
| https://lists.apache.org/thread/o90dd9lbk1hh3t2557t2y2qvrh92p7wy | Vendor Advisory |
| https://ofbiz.apache.org/download.html | Product |
| https://ofbiz.apache.org/security.html | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/09/03/6 | Mailing List |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-45195 | Third Party AdvisoryUS Government Resource |
Track CVE-2024-45195 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-45195), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.