Improper Authorization in OFBiz - CVE-2024-38856
Published: August 6, 2024 / Updated: February 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to missing permission checks when accessing ProgramExport and EntitySQLProcessor endpoints. A remote attacker can send specially crafted requests to the affected endpoints and execute arbitrary code.
Affected software
How to mitigate CVE-2024-38856
Links to Public Exploits and PoC-codes
- Exploit #11130 - Apache-OFBiz-Exploit (Exploit for Apache OFBiz - CVE-2024-38856) (February 12, 2025)
- Exploit #10959 - cve-2024-38856-poc (December 6, 2024)
- Exploit #10453 - CVE-2024-38856 (August 30, 2024)
- Exploit #10436 - CVE-2024-38856-ApacheOfBiz (Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15) (August 23, 2024)
- Exploit #10400 - CVE-2024-38856 (August 16, 2024)
- Exploit #10324 - CVE-2024-38856_Scanner (August 9, 2024)