CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Prediction
Documented as more likely to be exploited than 100.0% of known CVEs.
Aug 27, 2024
Sep 17, 2024
Threat Analysis
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
External Intelligence
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see:
https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2024-38856