'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2024-45507: Apache OFBiz Server-Side Request Forgery Vulnerability
Severity:critical
CVE ID:CVE-2024-45507
Descripiton:
|
Apache OFBiz is an enterprise resource planning(ERP) system from the Aoache Foundation. The System provides a complete set of java-based Web application components and tools. Versions earlier than Apache OFBiz 18.12.16 has server-side request forgery vulnerabilities that allow remote attackers to gain server permissions by controlling requests and injecting malicious code. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.