target entity

OFBiz

3 source-linked records in the current knowledge graph.

high

CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerability

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-45195EPSS 100.0%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38856: Apache OFBiz Incorrect Authorization Vulnerability

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38856EPSS 99.4%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2024-32113: Apache OFBiz Path Traversal Vulnerability

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-32113EPSS 99.4%ApacheOFBiz
CISA KEV ↗ · unattributed attribution