Skip to content
COOEY

EXPOSURES › CVE-2024-45195

CVE-2024-45195

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-02-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-45195 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildsql-injectionunpatcheddata-breach

Apache OFBiz allows remote attackers to bypass forced browsing restrictions and access unauthorized data via SQL injection.

Apache OFBiz contains a forced browsing vulnerability enabling remote attackers to inject SQL and access data beyond report permissions. DIB orgs must patch immediately to prevent unauthorized data exposure and potential compliance violations under FedRAMP/NIST 800-171.

Shame score — A known SQL injection vulnerability in a widely used Apache product that allows unauthorized data access via forced browsing bypass.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.