Executive brief
Apache OFBiz, an open-source enterprise resource planning (ERP) system used to manage business processes, is affected by a path traversal vulnerability. This flaw could allow an attacker to access sensitive files or directories on the server that should normally be restricted. Such access could lead to the exposure of configuration files, credentials, or other private business data.
Technical details
A path traversal vulnerability (CWE-22) exists in Apache OFBiz due to improper limitation of pathnames to restricted directories. An attacker can exploit this by sending specially crafted requests containing directory traversal sequences (e.g., ../) to access files outside of the intended web root or application directory. The vulnerability is present in versions prior to 24.09.06. Successful exploitation could result in the disclosure of sensitive system information or application source code. Users are advised to upgrade to version 24.09.06 to mitigate this risk.
Affected products
- Apache OFBiz before 24.09.06
Timeline
- 2026-05-19: disclosed: Initial advisory publication
- 2026-05-19: patched: Fix released in version 24.09.06