cbcvebase.

Apache Software Foundation Apache Ofbiz vulnerabilities

51 known vulnerabilities affecting apache_software_foundation/apache_ofbiz.

Total CVEs
51
CISA KEV
3
actively exploited
Public exploits
13
Exploited in wild
11
Severity breakdown
CRITICAL19HIGH15MEDIUM16LOW1

Vulnerabilities

Page 1 of 3
CVE-2024-32113P1CRITICALCVSS 9.8KEVPoCfixed in 18.12.132024-05-08
CVE-2024-32113 [CRITICAL] CWE-22 CVE-2024-32113: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
nvd
CVE-2024-38856P1CRITICALCVSS 9.8KEVPoC≤ 18.12.142024-08-05
CVE-2024-38856 [CRITICAL] CWE-863 CVE-2024-38856: Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18. Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explici
nvd
CVE-2024-45195P1HIGHCVSS 7.5KEVPoCfixed in 18.12.162024-09-04
CVE-2024-45195 [HIGH] CWE-425 CVE-2024-45195: Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
nvd
CVE-2023-51467P1CRITICALCVSS 9.8ExploitedPoCfixed in 18.12.112023-12-26
CVE-2023-51467 [CRITICAL] CWE-918 CVE-2023-51467: The vulnerability permits attackers to circumvent authentication processes, enabling them to remotel The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
nvd
CVE-2021-26295P1CRITICALCVSS 9.8ExploitedPoCvApache OFBiz 17.12.01 to 17.12.052021-03-22
CVE-2021-26295 [CRITICAL] CWE-502 CVE-2021-26295: Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
nvd
CVE-2023-49070P1CRITICALCVSS 9.8ExploitedPoCfixed in 18.12.102023-12-05
CVE-2023-49070 [CRITICAL] CWE-94 CVE-2023-49070: Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
nvd
CVE-2024-45507P1CRITICALCVSS 9.8ExploitedPoCfixed in 18.12.162024-09-04
CVE-2024-45507 [CRITICAL] CWE-94 CVE-2024-45507: Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulner Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
nvd
CVE-2024-36104P1CRITICALCVSS 9.1ExploitedPoCfixed in 18.12.142024-06-04
CVE-2024-36104 [CRITICAL] CWE-22 CVE-2024-36104: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.
nvd
CVE-2021-30128P1CRITICALCVSS 9.8ExploitedPoC≥ Apache OFBiz, < 17.12.072021-04-27
CVE-2021-30128 [CRITICAL] CWE-502 CVE-2021-30128: Apache OFBiz has unsafe deserialization prior to 17.12.07 version Apache OFBiz has unsafe deserialization prior to 17.12.07 version
nvd
CVE-2023-50968P1HIGHCVSS 7.5ExploitedPoC≤ 18.12.102023-12-26
CVE-2023-50968 [HIGH] CWE-200 CVE-2023-50968: Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.
nvd
CVE-2022-47501P2HIGHCVSS 7.5ExploitedPoC≥ 18.12.06, < 18.12.072023-04-14
CVE-2022-47501 [HIGH] CWE-22 CVE-2022-47501: Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a pre-authentication attack. This issue affects Apache OFBiz: before 18.12.07.
nvd
CVE-2021-29200P2CRITICALCVSS 9.8PoC≥ Apache OFBiz, < 17.12.072021-04-27
CVE-2021-29200 [CRITICAL] CWE-502 CVE-2021-29200: Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perfor Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
nvd
CVE-2018-8033P2HIGHCVSS 7.5PoCvApache OFBiz 16.11.01 to 16.11.042018-12-13
CVE-2018-8033 [HIGH] CWE-200 CVE-2018-8033: In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEng In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by havi
nvd
CVE-2024-25065P2CRITICALCVSS 9.1fixed in 18.12.122024-02-29
CVE-2024-25065 [CRITICAL] CWE-22 CVE-2024-25065: Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upg Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
nvd
CVE-2026-45434P2CRITICALCVSS 9.8fixed in 24.09.062026-05-19
CVE-2026-45434 [CRITICAL] CWE-287 CVE-2026-45434: Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remo Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
nvd
CVE-2025-54466P2CRITICALCVSS 9.8fixed in 24.09.022025-08-15
CVE-2025-54466 [CRITICAL] CWE-94 CVE-2025-54466: Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommended to upgrade to version 24.09.02, which fixes the
nvd
CVE-2022-25813P2HIGHCVSS 7.5≥ Apache OFBiz, ≤ 18.12.052022-09-02
CVE-2022-25813 [HIGH] CWE-1336 CVE-2022-25813: In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecomm In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.
nvd
CVE-2021-37608P2CRITICALCVSS 9.8≥ unspecified, ≤ 17.12.072021-08-18
CVE-2021-37608 [CRITICAL] CWE-434 CVE-2021-37608: Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.
nvd
CVE-2022-25371P2CRITICALCVSS 9.8≥ Apache OFBiz, ≤ 18.12.052022-09-02
CVE-2022-25371 [CRITICAL] CWE-22 CVE-2022-25371: Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data v Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.
nvd
CVE-2022-29063P2CRITICALCVSS 9.8≥ Apache OFBiz, ≤ 18.12.052022-09-02
CVE-2022-29063 [CRITICAL] CWE-502 CVE-2022-29063: The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on loca The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server restart, in order to run arbitrary code. Upgrade to at least 18.12.06 or appl
nvd