CVE Intel / CVE-2024-45195
CVE-2024-45195
ofbiz · apache
⚠
Actively exploited in the wild. Listed in the CISA Known Exploited Vulnerabilities catalogue: exploitation confirmed in the wild. Patch on priority.
What it is
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
Live exploitation on the huntback network (30 days)
60
attempts captured
15
distinct source IPs
2026-09-28
last seen
huntback carries a network signature for this CVE. Exploitation attempts are detected on the decoy fleet in real time.
How huntback helps
Deploy a decoy that emulates ofbiz and you will see every attempt at this CVE the moment it lands, with the full payload, the attacker's infrastructure, and any stage-2 loader. Then huntback can scan the attacker back.
CVSSn/a High
EPSS1.00 (99% pct)
In CISA KEVyes
Publishedn/a
Network detectableyes, signatured
Public exploitnone known