VulnerabilityModified
CVE-2023-49070
Pre-auth RCE in Apache Ofbiz 18.12.09.
CRITICAL 9.8EPSS 95.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 95.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 95.37% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- apache/ofbiz
- Source
- security@apache.org
References
- http://packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.html
- https://issues.apache.org/jira/browse/OFBIZ-12812Issue Tracking, Patch
- https://lists.apache.org/thread/jmbqk2lp4t4483whzndp5xqlq4f3otg3Mailing List
- https://ofbiz.apache.org/download.htmlProduct
- https://ofbiz.apache.org/release-notes-18.12.10.htmlRelease Notes
- https://ofbiz.apache.org/security.htmlVendor Advisory
- http://packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.html
- https://issues.apache.org/jira/browse/OFBIZ-12812Issue Tracking, Patch
- https://lists.apache.org/thread/jmbqk2lp4t4483whzndp5xqlq4f3otg3Mailing List
- https://ofbiz.apache.org/download.htmlProduct
- https://ofbiz.apache.org/release-notes-18.12.10.htmlRelease Notes
- https://ofbiz.apache.org/security.htmlVendor Advisory
- https://www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.