LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 4, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 25, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-45195 to its Known Exploited Vulnerabilities catalog on Feb 4, 2025, with a federal patch deadline of Feb 25, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

CVE-2024-45195 is a forced browsing vulnerability in Apache OFBiz. According to CISA, it allows a remote attacker to obtain unauthorized access. Apache OFBiz is commonly used for enterprise resource planning and related business functions, so unauthorized access can put operational data, configurations, and connected systems at risk. Teams should treat this as a priority for inventory and remediation, confirming all version and configuration details against the vendor advisory.

How it works

This issue is classified as CWE-425 (Forced Browsing). In this weakness class, an application fails to properly enforce access controls on resources that should be restricted. An attacker who can reach the application over the network may request URLs, paths, or endpoints that are not intended for unauthenticated or unauthorized users. Because the application does not adequately block or validate those requests, the attacker can retrieve content or invoke functionality that should be protected. The CISA summary states that a remote attacker can obtain unauthorized access; exact request patterns, parameters, or success conditions are not detailed in the provided facts and must be confirmed against the vendor advisory. No exploit code or step-by-step mechanics are supplied here, and defenders should not rely on incomplete public descriptions when building detections.

Am I affected? How to find it in your systems

Apache OFBiz typically runs as a Java-based enterprise application server, often deployed on internal or internet-facing hosts that support ERP, e-commerce, or back-office workflows. It may appear as a standalone service, container image, or package managed by operations teams.

If OFBiz is present but version or patch status is unclear, treat the instance as potentially affected until the vendor advisory is checked.

How to remediate

The primary action is to apply the mitigations or updates published by the Apache OFBiz project for this CVE. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. After applying the update:

If the vendor advisory lists additional configuration steps or work-arounds, implement those exactly as written.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the vendor fix.

If your data may have been exposed

Vulnerabilities that permit unauthorized access can lead to data exposure or further compromise if exploited. Known ransomware use is not documented for this CVE. If you suspect your environment was targeted, preserve logs, isolate affected systems, and follow your incident-response process. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApache · OFBiz
WeaknessCWE-425
Added to CISA KEVFeb 4, 2025
Federal patch deadlineFeb 25, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities