CVE-2024-38856 Details
Description
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
A vulnerability in Apache OFBiz prior to version 18.12.15 allows incorrect authorization, potentially leading to remote code execution. This issue arises because unauthenticated endpoints may execute screen rendering code without proper permission checks, depending on the screen definitions and endpoint configurations.
Users are advised to upgrade to Apache OFBiz version 18.12.15 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 31, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38856 | CISA-ADP | Third Party AdvisoryUS Government Resource |
| http://www.openwall.com/lists/oss-security/2024/08/04/1 | CVE | Mailing List |
| https://issues.apache.org/jira/browse/OFBIZ-13128 | [email protected] | Issue Tracking |
| https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w | [email protected] | Mailing ListVendor Advisory |
| https://ofbiz.apache.org/download.html | [email protected] | Product |
| https://ofbiz.apache.org/security.html | [email protected] | Patch |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apache OFBiz Incorrect Authorization Vulnerability | Aug 27, 2024 | Sep 17, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache ofbiz | < 18.12.15 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Dec 20, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 28, 2024 | Initial Analysis | [email protected] |
| Aug 28, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Aug 6, 2024 | CVE Modified | CISA-ADP |
| Aug 5, 2024 | New CVE Received | [email protected] |