CVE-2024-45195
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache OFBiz Forced Browsing Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-425
מוצרים מושפעים
apache: ofbiz
קישורים
- https://issues.apache.org/jira/browse/OFBIZ-13130 Issue TrackingVendor Advisory
- https://lists.apache.org/thread/o90dd9lbk1hh3t2557t2y2qvrh92p7wy Vendor Advisory
- https://ofbiz.apache.org/security.html Vendor Advisory
- https://ofbiz.apache.org/download.html Product
- http://www.openwall.com/lists/oss-security/2024/09/03/6 Mailing List
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… Third Party AdvisoryUS Government Resource