EXPOSURES › CVE-2024-45195
CVE-2024-45195
HIGH ⌖ ON CISA KEV · EXPLOITEDApache OFBiz allows remote attackers to bypass forced browsing restrictions and access unauthorized data via SQL injection.
Apache OFBiz contains a forced browsing vulnerability enabling remote attackers to inject SQL and access data beyond report permissions. DIB orgs must patch immediately to prevent unauthorized data exposure and potential compliance violations under FedRAMP/NIST 800-171.
Shame score — A known SQL injection vulnerability in a widely used Apache product that allows unauthorized data access via forced browsing bypass.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.