CVE-2024-45195 is a critical Direct Request ('Forced Browsing') vulnerability affecting Apache OFBiz versions prior to 18.12.16. This flaw allows unauthenticated attackers to achieve high confidentiality impact with low attack complexity, as indicated by its CVSS score of 7.5 (High). The vulnerability is actively exploited in the wild, listed in CISA's KEV catalog, and has garnered significant community attention and media coverage, including the availability of Nuclei templates for exploitation. Users are strongly advised to upgrade to Apache OFBiz version 18.12.16 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.12.16CPE matchmatch criteria | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* | ||
>= 0, < 18.12.16CPE match | cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.