Description
OFBiz has a authentication bypass vulnerability leading to RCE. An attacker can bypass the authentication with a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of OFBiz
References
Add permission check for view-maps and change defaults for request-maps
CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)
Related Vulnerabilities
TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-20114)
MySQL CVE-2015-0439 Vulnerability (CVE-2015-0439)
Oracle JRE CVE-2012-5067 Vulnerability (CVE-2012-5067)
MySQL Other Vulnerability (CVE-2003-0073)
Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-0305)