Lucene search

K
cvelistApacheCVELIST:CVE-2023-49070
HistoryDec 05, 2023 - 8:05 a.m.

CVE-2023-49070 Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

2023-12-0508:05:06
CWE-94
apache
www.cve.org
2
cve-2023-49070
pre-auth rce
apache ofbiz
xml-rpc
18.12.09
vulnerability
upgrade
18.12.10

9.7 High

AI Score

Confidence

High

0.798 High

EPSS

Percentile

98.3%

Pre-auth RCE in Apache Ofbiz 18.12.09.

Itโ€™s due to XML-RPCย no longer maintainedย still present.
This issue affects Apache OFBiz: before 18.12.10.ย 
Users are recommended to upgrade to version 18.12.10

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "18.12.10",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

9.7 High

AI Score

Confidence

High

0.798 High

EPSS

Percentile

98.3%