Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
Vulnerability Description
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49070
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Siebene@
References
- https://ofbiz.apache.org/download.html
- https://ofbiz.apache.org/security.html
- https://ofbiz.apache.org/release-notes-18.12.10.html
- https://issues.apache.org/jira/browse/OFBIZ-12812
- https://lists.apache.org/thread/jmbqk2lp4t4483whzndp5xqlq4f3otg3
- http://packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.html
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →