FAIL › dossier
OFBiz
PRODUCT· dossier confidence 20%
Apache OFBiz is an open-source ERP suite maintained by the Apache Software Foundation that has demonstrated a concerning security posture with multiple high-severity RCE vulnerabilities identified in 2024, including Groovy deserialization and SQL injection flaws.
PROFILE
Categoryopen-source softwareWhat they doApache OFBiz is an open-source enterprise resource planning (ERP) and business management suite developed by the Apache Software Foundation.
Websitehttps://ofbiz.apache.org ↗
SECURITY POSTURE
Apache OFBiz has a history of high-severity remote code execution (RCE) vulnerabilities, including multiple critical flaws in 2024 involving Groovy deserialization, path traversal, and SQL injection.
Notable failures
- CVE-2024-38856: Groovy RCE via unauthenticated user process
- CVE-2024-32113: Path traversal leading to RCE
- CVE-2024-45195: SQL injection bypassing forced browsing restrictions
Patterns: repeated high-severity RCE vulnerabilities in 2024; vulnerabilities in Groovy execution contexts; SQL injection in web tools
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-08-27 | CVE-2024-38856 | high | Apache OFBiz allows unauthenticated remote code execution via Groovy deserialization, enabling attackers to compromise ERP systems. |
| 2024-08-07 | CVE-2024-32113 | high | Apache OFBiz allows remote code execution via path traversal in authenticated report scenarios. |
| 2025-02-04 | CVE-2024-45195 | high | Apache OFBiz allows remote attackers to bypass forced browsing restrictions and access unauthorized data via SQL injection. |
DOSSIER SOURCES
- Company Database Search · www.edgarcompany.sec.gov
- Building and running OFBiz using Docker - The Apache Software Foundation · nightlies.apache.org
- OFBiz: Web Tools: Login · admin.rzj.plus
- OFBiz: Marketing Manager: Login · www.learnbfsi.com
- OFBiz: Marketing Manager: Login - learnbfsi.com · www.learnbfsi.com
Open questions: Current patch status for CVE-2024-38856, CVE-2024-32113, and CVE-2024-45195 · Frequency of security advisories in 2025 · Impact of vulnerabilities on CMMC compliance
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:45:38.545635+00:00