CVE-2024-38856
About
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to version 18.12.15, which fixes the issue.
Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
Rainforest analyst review
The flaw is an incorrect authorization issue in Apache OFBiz through 18.12.14. Certain endpoints that should be unauthenticated do not properly enforce permission checks before rendering screens, and where screen definitions rely on the endpoint's configuration rather than checking the user's permissions themselves, an unauthenticated attacker can invoke screen-rendering logic they should not reach. Chained appropriately, that exposure lets an attacker drive the application into executing code, so the practical impact is remote code execution against a default-configured instance.
OFBiz is an open-source ERP and e-commerce framework that underpins order management, accounting, and customer data, so a compromised instance exposes sensitive business records and can serve as a pivot into the surrounding environment. This CVE stems from an authorization-bypass pattern that has been repeatedly probed in OFBiz, and public exploit code circulated after disclosure, so internet-facing deployments should be treated as targeted. Upgrade to 18.12.15 or later, keep the application behind access controls rather than openly exposed, and review the host for unexpected process execution and the application logs for anomalous requests to control and view endpoints.
References
- https://issues.apache.org/jira/browse/OFBIZ-13128
- https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w
- https://ofbiz.apache.org/download.html
- https://ofbiz.apache.org/security.html
- http://www.openwall.com/lists/oss-security/2024/08/04/1
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38856
Related CVEs
Frequently asked questions
What is CVE-2024-38856?
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue.
How severe is CVE-2024-38856?
CVE-2024-38856 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2024-38856 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2024-38856?
Public advisories list the following as affected: ofbiz. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2024-38856?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
