high Known exploitedREV. 01
CVE-2024-45195Apache OFBiz — Forced Browsing to Unauthorized Screens
Apache OFBiz serves screens to callers who request them directly, without checking that they were ever allowed to get there.
Read the risk
THE VITAL STATS- CVSS score
- 7.5/ 10 CVSS v3.1
- EPSS probability
- 100% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2024-09-04
- Added to KEV
- 2025-02-04
- Exploit published
- Not recorded
- Confidence
- medium
- Kill chain
- discovery
- MITRE ATT&CK
- T1190
- Severity
- high
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attacker needsNetwork access to the application
Fixed inApache OFBiz 18.12.16
Behind the card
5 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02CISACISA Known Exploited Vulnerabilities catalogcisa.gov
- 03Vendor advisoryissues.apache.orgissues.apache.org
- 04Vendor advisorylists.apache.orglists.apache.org
- 05Vendor advisoryofbiz.apache.orgofbiz.apache.org
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| exploitation.known_exploited, exploitation.kev_added | cisa.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-08-07 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.