
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54466 is a Code Injection vulnerability (CWE-94) in the Apache OFBiz scrum plugin that can lead to Remote Code Execution (RCE) by unauthenticated attackers. It affects Apache OFBiz versions before 24.09.02 only when the scrum plugin is enabled. The vulnerability was discovered by Teeramet Eakwilai, Thanasin Luangpipat, and Jarukit Auikritskul, disclosed publicly on August 5, 2025 via the oss-security mailing list, and assigned a CVSS v3.1 base score of 9.8 (Critical) (oss-security, Red Hat CVE).
The root cause is improper control of code generation (CWE-94) within the Apache OFBiz scrum plugin, where user-supplied input is not adequately sanitized before being used in code execution contexts. An unauthenticated remote attacker can send a crafted network request to the vulnerable scrum plugin endpoint, triggering arbitrary code injection and execution on the server without requiring any credentials or user interaction. The vulnerability is only present when the scrum plugin is actively deployed; installations without the plugin are not affected. The issue is tracked upstream as OFBIZ-13276 (oss-security, Apache Jira).
Successful exploitation grants an unauthenticated attacker full remote code execution on the affected Apache OFBiz server, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could exfiltrate sensitive business data (ERP records, customer data, financial information), modify or destroy data, install persistent backdoors, and use the compromised server as a pivot point for lateral movement within the internal network (oss-security, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.066%, reflecting a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. No threat actor attribution has been reported. However, the zero-authentication requirement and critical CVSS score make it a high-priority target if a public exploit becomes available.
/bin/bash, cmd.exe, curl, wget, python, powershell); unexpected network listeners opened by the Java process.The primary remediation is to upgrade Apache OFBiz to version 24.09.02 or later, which contains the fix for this vulnerability (oss-security, Apache Security). If an immediate upgrade is not feasible, disable the scrum plugin to eliminate the attack surface. Additionally, implement network segmentation to restrict access to the OFBiz instance to trusted networks only, and monitor for unusual system activity. Review the release notes for version 24.09.02 for full details on the fix (Apache Release Notes).
The vulnerability was disclosed via the oss-security mailing list on August 5, 2025, by Nicolas Malin on behalf of the Apache OFBiz security team (oss-security). Red Hat has acknowledged the CVE and published an advisory (Red Hat CVE). Check Point and Trend Micro have also catalogued the vulnerability in their threat encyclopedias. Community discussion has been limited, with no major public controversy or notable researcher commentary beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."