Executive brief
Apache OFBiz is vulnerable to a Direct Request ('Forced Browsing') flaw that allows remote attackers to bypass authorization. By accessing restricted resources directly, an unauthenticated user can obtain unauthorized access to sensitive information or functionality.
Affected products
- Apache OFBiz before 18.12.16
Timeline
- 2024-09-04: disclosed: Initial CVE publication by Apache Software Foundation
- 2024-09-04: patched: Version 18.12.16 released to address the issue
- 2025-02-04: kev added: CISA added CVE-2024-45195 to the Known Exploited Vulnerabilities (KEV) catalog
- 2025-02-04: exploited: Reported as exploited in the wild per CISA KEV entry