Apache Addresses Persistent RCE Flaw in OFBiz

Red | Vulnerability Report
Download PDF

Apache has addressed a critical security vulnerability in its open-source OFBiz software, identified as CVE-2024-45195. This remote code execution (RCE) flaw stems from a forced browsing weakness, which allows attackers to bypass access controls and gain access to restricted paths. By exploiting this vulnerability, an unauthenticated attacker could send specially crafted requests, leading to the execution of arbitrary code on the affected system.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox