CVE-2024-25065

CRITICAL

Apache OFBiz <18.12.12 - Path Traversal

Title source: llm
STIX 2.1

Description

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Scores

CVSS v3 9.1
EPSS 0.0081
EPSS Percentile 74.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
apache/ofbiz < 18.12.12
Published Feb 29, 2024
Tracked Since Feb 18, 2026