CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-02-04. EPSS: 100% chance of exploitation in the next 30 days.
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Affected products
- Apache OFBiz: before 18.12.16 (fixed in 18.12.16)
Published 2024-09-04. Last modified 2026-06-17.