Apache OFBiz
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*, +1 more
- < 18.12.16
This vulnerability is being actively exploited in the wild.
A forced browsing vulnerability has been identified in Apache OFBiz versions prior to 18.12.16. This vulnerability allows unauthorized access to rendered views by exploiting confused controller-view authorization logic. Users are advised to upgrade to version 18.12.16, which addresses this issue by introducing a new permission check for view-maps and changing the default settings for request-maps.
Exploitation of this vulnerability could lead to unauthorized access to views that should be restricted, allowing users to view or interact with content or functionality they are not permitted to access.
Users can upgrade to Apache OFBiz version 18.12.16 to address this vulnerability. Instructions for downloading this version are available on the Apache OFBiz download page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.