Skip to content
COOEY

FAIL › dossier

OFBiz

PRODUCT

· dossier confidence 20%

Apache OFBiz is an open-source ERP suite maintained by the Apache Software Foundation that has demonstrated a concerning security posture with multiple high-severity RCE vulnerabilities identified in 2024, including Groovy deserialization and SQL injection flaws.

PROFILE
Categoryopen-source softwareWhat they doApache OFBiz is an open-source enterprise resource planning (ERP) and business management suite developed by the Apache Software Foundation. Websitehttps://ofbiz.apache.org ↗
SECURITY POSTURE

Apache OFBiz has a history of high-severity remote code execution (RCE) vulnerabilities, including multiple critical flaws in 2024 involving Groovy deserialization, path traversal, and SQL injection.

Notable failures
  • CVE-2024-38856: Groovy RCE via unauthenticated user process
  • CVE-2024-32113: Path traversal leading to RCE
  • CVE-2024-45195: SQL injection bypassing forced browsing restrictions
Patterns: repeated high-severity RCE vulnerabilities in 2024; vulnerabilities in Groovy execution contexts; SQL injection in web tools
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2024-08-27 CVE-2024-38856 high Apache OFBiz allows unauthenticated remote code execution via Groovy deserialization, enabling attackers to compromise ERP systems.
2024-08-07 CVE-2024-32113 high Apache OFBiz allows remote code execution via path traversal in authenticated report scenarios.
2025-02-04 CVE-2024-45195 high Apache OFBiz allows remote attackers to bypass forced browsing restrictions and access unauthorized data via SQL injection.
Open questions: Current patch status for CVE-2024-38856, CVE-2024-32113, and CVE-2024-45195 · Frequency of security advisories in 2025 · Impact of vulnerabilities on CMMC compliance
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:45:38.545635+00:00