Lucene search

K
cvelistApacheCVELIST:CVE-2023-51467
HistoryDec 26, 2023 - 2:46 p.m.

CVE-2023-51467 Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

2023-12-2614:46:59
apache
www.cve.org
1
apache ofbiz
pre-authentication
rce
vulnerability
code execution

9.9 High

AI Score

Confidence

High

0.639 Medium

EPSS

Percentile

97.9%

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "18.12.11",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

9.9 High

AI Score

Confidence

High

0.639 Medium

EPSS

Percentile

97.9%