Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2024-38856
PUBLISHEDApache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
- Vendor
- Apache Software Foundation
- Product
- Apache OFBiz
- Published
- Aug 05, 2024
- EPSS
- —
Description
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Aug 27, 2024 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/apache_ofbiz_forgot_password_directory_traversal.rb | Apr 28, 2025 |
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-38856.yaml | Apr 25, 2025 |
| Nessus | https://www.tenable.com/plugins/nessus/206393 | Aug 30, 2024 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
metasploit · Created Unknown
Metasploit module for CVE-2024-38856
github · Created 2024-08-28 03:17:22 UTC · 3 stars
Apache OFBiz CVE-2024-38856
github · Created 2024-08-10 03:05:34 UTC · 2 stars
Perform With Massive Apache OFBiz Zero-Day Scanner & RCE
github · Created 2024-08-08 02:40:56 UTC · 43 stars
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Added to KEVIntel
-
Detected by Nessus
-
Detected by Nuclei
-
Detected by Metasploit