CVE CVE

CVE-2024-32113

CISA Known Exploited Vulnerability (KEV)

Apache OFBiz Path Traversal Vulnerability

August 7, 2024

August 28, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.

Users are recommended to upgrade to version 18.12.13, which fixes the issue.

Weakness Enumeration

CWE-ID CWE Name

CWE-22
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)

Known Affected Software Configurations


cpe:2.3:a:apache:ofbiz:18.12.13:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.14:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.15:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.12:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.11:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.10:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.09:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.07:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.09:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.02:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.03:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.05:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:18.12.06:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.05:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.06:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.08:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.07:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.03:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:17.12.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:16.11.07:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:16.11.06:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:16.11.05:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:10.04.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:09.04.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:09.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:-:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:16.11.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:16.11.03:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:16.11.02:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:16.11.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:13.07.02:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:12.04.05:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:10.04.06:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:10.04.05:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:10.04.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:10.04.03:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:10.04.02:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:10.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:9.04.02:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:9.04.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:9.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:13.07.03:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:13.07:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:12.04.06:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:12.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:11.04.06:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:11.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:13.07.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:12.04.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:12.04.03:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:12.04.02:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:12.04.01:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:11.04.05:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:11.04.04:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:11.04.03:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:11.04.02:*:*:*:*:*:*:*

cpe:2.3:a:apache:ofbiz:11.04.01:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined