Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
https://lists.apache.org/thread/o90dd9lbk1hh3t2557t2y2qvrh92p7wy
https://www.securityweek.com/cisa-issues-exploitation-warning-for-net-vulnerability/
https://www.cisa.gov/news-events/alerts/2025/02/04/cisa-adds-four-known-exploited-vulnerabilities-catalog
https://securityonline.info/hackers-target-apache-ofbiz-rce-flaw-cve-2024-45195-after-poc-exploit-released
https://ofbiz.apache.org/security.html
https://ofbiz.apache.org/download.html
https://issues.apache.org/jira/browse/OFBIZ-13130
http://www.openwall.com/lists/oss-security/2024/09/03/6
Source: Mitre, NVD
Published: 2024-09-04
Updated: 2025-02-05
Known Exploited Vulnerability (KEV)
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N
Severity: High
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.94081