S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 1, 2024

CVE-2024-45195 Scanner

CVE-2024-45195 scanner - Remote Code Execution vulnerability in Apache OFBiz

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-45195
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache OFBizby Apache Software Foundation
AFFECTED< 18.12.16SAFE ✓≥ 18.12.16
ofbizby apache
AFFECTED< 18.12.16SAFE ✓≥ 18.12.16
Updated Aug 22, 2026View on NVD →
Detail

Apache OFBiz is a comprehensive suite of enterprise applications built on a common architecture that organizations use for enterprise resource planning (ERP), customer relationship management (CRM), e-commerce, and more. Businesses across various industries deploy OFBiz to streamline their operations. This software is typically utilized by IT departments, system administrators, and developers to manage business processes. Apache OFBiz is open source and highly customizable, making it popular among users with specific business requirements. However, like many complex systems, it can be vulnerable to various cyber threats.

The vulnerability in Apache OFBiz allows for unauthenticated remote code execution on systems running versions below 18.12.16. This occurs due to missing view authorization checks, enabling attackers to send malicious requests that result in arbitrary code execution. Exploiting this vulnerability could lead to full system compromise without the need for user credentials. The issue has been fixed in version 18.12.16.

The vulnerability stems from the lack of authorization checks in certain web application views of Apache OFBiz. Specifically, attackers can send crafted HTTP requests to the "forgotPassword/xmldsdump" endpoint, manipulating the "outpath" parameter to upload and execute arbitrary files. The absence of proper validation allows unauthorized users to create and access files on the server, leading to code execution. The vulnerability affects both Linux and Windows environments, making the exposure broad.

If exploited, the vulnerability could allow attackers to execute arbitrary code on the server, potentially leading to full system compromise. Malicious actors could install backdoors, steal sensitive information, or disrupt business operations. The lack of authentication requirements makes this particularly dangerous, as anyone with access to the internet can target vulnerable instances. Organizations running affected versions may face severe security risks, including data breaches and operational disruptions.

By using S4E, you can proactively manage your exposure to cyber threats like Remote Code Execution vulnerabilities in critical software such as Apache OFBiz. Our platform helps you stay ahead by identifying vulnerabilities before attackers can exploit them, offering comprehensive reporting and remediation guidance. With real-time monitoring and actionable insights, S4E ensures your digital assets remain secure. Sign up today and safeguard your infrastructure with industry-leading vulnerability management.

References:

Solution Advice
  • Upgrade Apache OFBiz to version 18.12.16 or later.
  • Implement strong access controls to limit exposure to sensitive endpoints.
  • Regularly audit and monitor access logs for suspicious activity.
  • Apply patches and updates to all business-critical software on time.
  • Isolate vulnerable instances from public access until they are secured.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.