Pre-auth RCE in Apache Ofbiz 18.12.09.
Itโs due to XML-RPCย no longer maintainedย still present.
This issue affects Apache OFBiz: before 18.12.10.ย
Users are recommended to upgrade to version 18.12.10
[
{
"defaultStatus": "affected",
"product": "Apache OFBiz",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "18.12.10",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
]