CVE-2023-49070: Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
Published Dec 4, 2023
·Updated
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
Affected Software
2 affected components
Apache OFBiz<18.12.10
Apache OFBiz=18.12.11
Remediation
Patch Available
Event History
Dec 5, 2023
CVE Published
via MITRE·08:05 AM
Data Sourced
via MITRE·08:05 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 28, 2023
News Published
04:20 PM
Jan 8, 2024
News Published
via The Register·05:45 PM
Jan 20, 2024
News Published
via The Register·05:49 PM
Sep 5, 2024
News Published
via BleepingComputer·09:33 PM
News Published
via BleepingComputer·09:34 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-49070?
CVE-2023-49070 is considered a critical vulnerability as it allows pre-authentication remote code execution.
2
How do I fix CVE-2023-49070?
To mitigate CVE-2023-49070, users should upgrade Apache OFBiz to version 18.12.10 or later.
3
Which versions of Apache OFBiz are affected by CVE-2023-49070?
CVE-2023-49070 affects all versions of Apache OFBiz before 18.12.10.
4
What component is responsible for the vulnerability in CVE-2023-49070?
The vulnerability in CVE-2023-49070 is due to an outdated and unmaintained XML-RPC component.
5
Is there a workaround for CVE-2023-49070 if I cannot upgrade immediately?
There is no official workaround for CVE-2023-49070, so upgrading to the fixed version is strongly recommended.