CVE Database
/

CVE-2024-38856

Back to search

CVE-2024-38856

Published: Aug 5, 2024

Modified: Oct 21, 2025

PUBLISHED

Description

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

VendorProductVersions

Apache Software Foundation

Apache OFBiz

affected
0 - <= 18.12.14

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now