Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
| Vendor | Product | Versions |
|---|---|---|
| apache | ofbiz | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | ofbiz | cert_advisory | 90% |
Updated description with new technical details, added CWE-94, and marked the vulnerability as actively exploited with an exploit available.
Updated affected versions to include 24.09.05, changed severity to HIGH, and noted that no exploit is available.
Initial creation