Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-49070
HistoryDec 05, 2023 - 8:15 a.m.

Code injection

2023-12-0508:15:00
PRIOn knowledge base
www.prio-n.com
5
code injection
remote code execution
apache ofbiz
security vulnerability
xml-rpc
software upgrade

7.2 High

AI Score

Confidence

Low

0.798 High

EPSS

Percentile

98.3%

Pre-auth RCE in Apache Ofbiz 18.12.09.

Itโ€™s due to XML-RPCย no longer maintainedย still present.
This issue affects Apache OFBiz: before 18.12.10.ย 
Users are recommended to upgrade to version 18.12.10

CPENameOperatorVersion
ofbizlt18.12.10

7.2 High

AI Score

Confidence

Low

0.798 High

EPSS

Percentile

98.3%