CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerability
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
Other sources
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrade to version 18.12.16, which fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache OFBizto a version that resolves this vulnerability.Fixed in 18.12.16 - Compensating control
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-45195?
CVE-2024-45195 is considered a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-45195?
To fix CVE-2024-45195, upgrade Apache OFBiz to version 18.12.16 or later.
What is the nature of the vulnerability in CVE-2024-45195?
CVE-2024-45195 is a forced browsing vulnerability that allows remote attackers to gain unauthorized access.
Which versions of Apache OFBiz are affected by CVE-2024-45195?
Apache OFBiz versions before 18.12.16 are affected by CVE-2024-45195.
Who is vulnerable to CVE-2024-45195?
Any users of Apache OFBiz prior to version 18.12.16 are vulnerable to CVE-2024-45195.