Security Advisory

CVE-2023-49070

9.8
CRITICAL

Vulnerability Description

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10
Published Date December 5, 2023
Official Source NIST NVD Advisory