← Vulnerability feed

Vulnerability record · CVE-2024-45507 · published 4 September 2024

CVE-2024-45507: Apache OFBiz SSRF and code injection before 18.12.16

Apache · Ofbiz

Apache OFBiz before 18.12.16 is affected by a server-side request forgery flaw combined with improper control of code generation (code injection). The vendor recommends upgrading to 18.12.16, which fixes the issue. Because the flaw is network-reachable and requires no authentication or user interaction, it is a serious risk to exposed OFBiz instances.

9.8 CVSS 3.1 Critical EPSS 93% · top 0.2% CWE-94 · Code injectionCWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and a very high EPSS probability make this an urgent patch.

What it is

Apache OFBiz before 18.12.16 is affected by a server-side request forgery flaw combined with improper control of code generation (code injection). The vendor recommends upgrading to 18.12.16, which fixes the issue. Because the flaw is network-reachable and requires no authentication or user interaction, it is a serious risk to exposed OFBiz instances.

Impact

An unauthenticated attacker could make the server issue requests to internal or external systems and, through the code injection component, potentially execute code in the OFBiz context. This can lead to full compromise of confidentiality, integrity and availability of the application and its host.

Attack surface

Reachable over the network via HTTP against an exposed OFBiz instance, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

The record does not list this CVE in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.93229, 99.83rd percentile), indicating a strong likelihood of exploitation activity. Reference tags include Patch and Vendor Advisory but no public exploit tag.

What to do

  • Upgrade Apache OFBiz to 18.12.16 or later as the primary fix.
  • If immediate upgrade is not possible, restrict network access to OFBiz management and application endpoints to trusted sources only.
  • Place OFBiz behind a reverse proxy or WAF and block requests to internal/private address ranges to reduce SSRF reach.
  • Monitor vendor advisories and the OFBIZ-13132 issue for any additional guidance.
  • Review and harden any server-side request or code-generation functionality exposed by the application.

Detection

  • Monitor OFBiz server logs for outbound requests to internal or unexpected external hosts originating from the application.
  • Alert on unusual HTTP requests to OFBiz endpoints from unauthenticated or unexpected sources.
  • Watch for signs of code execution or unexpected child processes spawned by the OFBiz service.
  • Correlate network egress from OFBiz hosts with known internal address ranges to catch SSRF attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45507 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2024-45507), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.