logo

Apache fixes critical OFBiz remote code execution vulnerability

ID: b508bddf-00a1-5bb9-aa3b-0a312562edbf

STIX ID: report--b508bddf-00a1-5bb9-aa3b-0a312562edbf

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-09-05

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Apache fixed a critical unauthenticated remote code execution vulnerability in OFBiz (CVE-2024-45195) that allows attackers to bypass view authorization and execute arbitrary code; Rapid7 published a report with PoC and the issue patches previous CVEs with the same root cause. Users are urged to upgrade to OFBiz 18.12.16 immediately, as related OFBiz flaws have been actively exploited and have been added to CISA's known-exploited vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.