Critical severity9.8NVD Advisory· Published Dec 5, 2023· Updated Jun 17, 2026
CVE-2023-49070
CVE-2023-49070
Description
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
7- issues.apache.org/jira/browse/OFBIZ-12812nvdIssue TrackingPatch
- ofbiz.apache.org/security.htmlnvdVendor Advisory
- lists.apache.org/thread/jmbqk2lp4t4483whzndp5xqlq4f3otg3nvdMailing List
- ofbiz.apache.org/download.htmlnvdProduct
- ofbiz.apache.org/release-notes-18.12.10.htmlnvdRelease Notes
- packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.htmlnvd
- www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467nvd
News mentions
0No linked articles in our index yet.