← back
CVE-2023-49070observed exploitationCWE-94

Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 95%
from disclosure to weapon9 days
Published on NVDDec 5
1st PoC+9d
metasploitJul 13
VulnCheck+24d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
8 public exploit(s)
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.