CVE-2023-49070
published 2023-12-05CVE-2023-49070: Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are…
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
95.44%
99.9th percentile
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present.
This issue affects Apache OFBiz: before 18.12.10.
Users are recommended to upgrade to version 18.12.10
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 18.12.10 | 18.12.10 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | < 18.12.10 | 18.12.10 |
Detection & IOCsextracted from sources · hover to see the quote
yara↗
APP.EXPLOIT.CVE-2023-49070
- →The vulnerable unauthenticated endpoint is /webtools/control/xmlrpc — monitor HTTP requests (especially POST with XML body) to this path on Apache OFBiz instances as a primary detection point. ↗
- →Active exploitation attempts use PoC payloads that force vulnerable servers to make outbound DNS/HTTP connections to oast.online — monitor for unexpected outbound connections to this domain from OFBiz servers. ↗
- →Exploitation leverages Java deserialization via the ROME gadget chain (older versions) or CommonsBeanutils1 gadget chain (18.12.x with auth bypass). Detect serialized Java payloads in HTTP POST bodies to /webtools/control/xmlrpc. ↗
- →Nuclei template for CVE-2023-49070 uses a DNS interaction check — look for the faultString keyword in HTTP responses as a secondary indicator of a vulnerable OFBiz instance. ↗
- →Attackers scanning for CVE-2023-49070 are specifically interested in identifying vulnerable Confluence servers — correlate OFBiz exploitation attempts with subsequent Confluence-targeted activity. ↗
- →Post-exploitation: look for the OFBiz Derby database credential file at /opt/ofbiz/runtime/data/derby/ofbiz/seg0/ containing hashed passwords in the format $SHA$<salt>$<base64hash>. ↗
- ·The Metasploit module switches gadget chains depending on version: ROME for pre-17.12.01, CommonsBeanutils1 for 18.12.x with CVE-2023-51467 auth bypass — detection rules must account for both payload types. ↗
- ·All versions 18.12.9 and below are impacted by CVE-2023-49070; all versions 18.12.10 and below are additionally impacted by CVE-2023-51467 — version-based blocking must use 18.12.11 as the minimum safe version for the combined risk. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
vendor_apache9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9rm6-p86c-42xm: Pre-auth RCE in Apache Ofbiz 18
ghsa_unreviewed·2023-12-05
CVE-2023-49070 [CRITICAL] CWE-94 GHSA-9rm6-p86c-42xm: Pre-auth RCE in Apache Ofbiz 18
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present.
This issue affects Apache OFBiz: before 18.12.10.
Users are recommended to upgrade to version 18.12.10
VulnCheck
Apache OFBiz Improper Control of Generation of Code ('Code Injection')
vulncheck·2023·CVSS 9.8
CVE-2023-49070 [CRITICAL] Apache OFBiz Improper Control of Generation of Code ('Code Injection')
Apache OFBiz Improper Control of Generation of Code ('Code Injection')
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present.
This issue affects Apache OFBiz: before 18.12.10.
Users are recommended to upgrade to version 18.12.10
Affected: Apache OFBiz
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-29&host_type=src&vulnerability=cve-2023-49070; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-30&host_type=src&vulnerability=cve-2023-49070; https://dashboard.shadowserver.org/statistics/honeypot/v
Apache
Apache ofbiz: CVE-2023-49070
vendor_apache·CVSS 9.8
CVE-2023-49070 [CRITICAL] Apache ofbiz: CVE-2023-49070
Apache ofbiz: CVE-2023-49070
; affected release 18.12.09; fixed in 18.12.10 with commit c59336f604
Suricata
ET WEB_SPECIFIC_APPS Apache OFBiz Authentication Bypass Vulnerability (CVE-2023-49070)
suricata·2024-01-12·CVSS 9.8
CVE-2023-49070 [CRITICAL] ET WEB_SPECIFIC_APPS Apache OFBiz Authentication Bypass Vulnerability (CVE-2023-49070)
ET WEB_SPECIFIC_APPS Apache OFBiz Authentication Bypass Vulnerability (CVE-2023-49070)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Apache OFBiz Authentication Bypass Vulnerability (CVE-2023-49070)"; flow:established,to_server; http.method; content:"POST"; http.uri; content: "/webtools/control/xmlrpc"; startswith; fast_pattern; content:"/?"; within:3; content:"USERNAME"; content:"PASSWORD"; content:"requirePasswordChange=Y"; http.request_body; content:"|3c 3f|xml version|3d 22|1.0|22 3f 3e|"; startswith; content:"|3c|methodCall|3e|"; within:30; content:"|3c|serializable xmlns|3d 22|http|3a 2f 2f|ws.apache.org/xmlrpc/namespaces/extensions|22 3e|"; within:500; reference:url,attackerkb.com/topics/OitLfY28up/cve-2023-49070?referrer=activityFeed; reference:url
Nuclei
Apache OFBiz < 18.12.10 - Arbitrary Code Execution
nuclei·CVSS 9.8
CVE-2023-49070 [CRITICAL] Apache OFBiz < 18.12.10 - Arbitrary Code Execution
Apache OFBiz
{{randstr}}
test
{{generate_java_gadget("dns", "http://{{interactsh-url}}", "base64")}}
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "dns"
- type: word
part: body
words:
- 'faultString'
# digest: 4b0a00483046022100fcc3b0d067cdfdeaff7e35e1e4530f3636ebd0f4f963feac0dcdcefc254f2a1f022100d0e693c097846d534173091e2f324ca4fc90139b2ff046f3235a0f237f3180e7:922c64590222798bb761d5b6d8e72950
Metasploit
Apache OFBiz XML-RPC Java Deserialization
metasploit·CVSS 9.8
CVE-2023-51467 [CRITICAL] Apache OFBiz XML-RPC Java Deserialization
Apache OFBiz XML-RPC Java Deserialization
This module exploits a Java deserialization vulnerability in Apache OFBiz's unauthenticated XML-RPC endpoint /webtools/control/xmlrpc for versions prior to 17.12.01 using the ROME gadget chain. Versions up to 18.12.11 are exploitable utilizing an auth bypass CVE-2023-51467 and use the CommonsBeanutils1 gadget chain. Verified working on 18.12.09, 17.12.01, and 15.12
Bleepingcomputer
Apache fixes critical OFBiz remote code execution vulnerability
blogs_bleepingcomputer·2024-09-05·CVSS 9.8
[CRITICAL] Apache fixes critical OFBiz remote code execution vulnerability
## Apache fixes critical OFBiz remote code execution vulnerability
## Sergiu Gatlan
Apache has fixed a critical security vulnerability in its open-source OFBiz (Open For Business) software, which could allow attackers to execute arbitrary code on vulnerable Linux and Windows servers.
OFBiz is a suite of customer relationship management (CRM) and enterprise resource planning (ERP) business applications that can also be used as a Java-based web framework for developing web applications.
Tracked as CVE-2024-45195 and discovered by Rapid7 security researchers, this remote code execution flaw is caused by a forced browsing weakness that exposes restricted paths to unauthenticated direct request attacks.
"An attacker with no valid credentials can exploit missing view authorization checks in
Zscaler
CVE-2023-51467 | ThreatLabz
blogs_zscaler·2024-01-08·CVSS 9.8
[CRITICAL] CVE-2023-51467 | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bleepingcomputer
Apache OFBiz RCE flaw exploited to find vulnerable Confluence servers
blogs_bleepingcomputer·2023-12-28·CVSS 9.8
[CRITICAL] Apache OFBiz RCE flaw exploited to find vulnerable Confluence servers
## Apache OFBiz RCE flaw exploited to find vulnerable Confluence servers
## Bill Toulas
A critical Apache OFBiz pre-authentication remote code execution vulnerability is being actively exploited using public proof of concept (PoC) exploits.
Apache OFBiz (Open For Business) is an open-source enterprise resource planning system many businesses use for e-commerce inventory and order management, human resources operations, and accounting.
OFBiz is part of Atlassian JIRA, a commercial project management and issue-tracking software used by over 120,000 companies worldwide. Therefore, any flaws in the open-source project are inherited by Atlassian's product.
This authentication bypass flaw is tracked as CVE-2023-49070 and was fixed in OFBiz version 18.12.10, released on December 5, 2023.
Th
Zscaler
CISO Monthly Roundup, January 2024: Zero day VPN vulnerabilities, DreamBus, ZLoader, Qakbot, and recent security advisories | CXO Revolutionaries
blogs_zscaler·CVSS 4.9
[MEDIUM] CISO Monthly Roundup, January 2024: Zero day VPN vulnerabilities, DreamBus, ZLoader, Qakbot, and recent security advisories | CXO Revolutionaries
EDITOR'S PICK
## CISO Monthly Roundup, January 2024: Zero day VPN vulnerabilities, DreamBus, ZLoader, Qakbot, and recent security advisories
Deepen Desai
Contributor
Zscaler
## Feb 13, 2024
In the latest edition of the CISO Monthly Roundup we examine recent zero day VPN vulnerabilities and offer threat analysis on DreamBus, ZLoader, and Qakbot. We also take a look at recent security advisories and offer our insights.
The CISO Monthly Roundup provides the latest threat research from the ThreatLabz team, along with CISO insights on other cyber-related subjects. Over the past month ThreatLabz has examined Ivanti VPN vulnerabilities, performed a deep dive on Qakbot, analyzed new DreamBus modules, discovered new Zloader capabilities and addressed relevant security advisories.
## Critica
CTF
easy / README
ctf_writeups·CVSS 6.0
[MEDIUM] easy / README
---
layout: default
title: Easy Machines
parent: Machines
nav_order: 1
description: "120+ Easy HTB machine writeups with walkthroughs"
permalink: /machines/easy/
---
# HackTheBox Easy Machines - Comprehensive Reference
> Complete catalog of retired HTB Easy machines with OS, key vulnerability, attack path summary, and quality writeup links.
**Total: 100+ Easy Machines** | Updated: April 2026
---
## Quick Navigation
- [Classic / Legacy Machines (2017-2019)](#classic--legacy-machines-2017-2019)
- [2019-2020 Machines](#2019-2020-machines)
- [2021 Machines](#2021-machines)
- [2022 Machines](#2022-machines)
- [2023 Machines](#2023-machines)
- [2024 Machines (Season 4 & 5)](#2024-machines-season-4--5)
- [2025-2026 Machines (Season 6+)](#2025-2026-machines-season-6)
---
## Classic / Legac
CTF
Bizness / README
ctf_writeups·CVSS 9.8
CVE-2023-49070 [CRITICAL] Bizness / README
# Bizness - HackTheBox - Writeup
Linux, 20 Base Points, Easy
## Machine
## TL;DR
To solve this machine, we start by using `nmap` to enumerate open services and find ports `22`, `80`, and `443`.
***User***: Identified Apache OFBiz as vulnerable to `CVE-2023-49070` and obtained Remote Code Execution (RCE) as the `ofbiz` user.
***Root***: Discovered the hashed password in the `.dat` file along with instructions on its creation in the `docker-entrypoint.sh` file. Decrypted the password, revealing the `root` password.
## Bizness Solution
### User
Let's begin by using `nmap` to scan the target machine:
```console
┌─[evyatar9@parrot]─[/hackthebox/Bizness]
└──╼ $ nmap -sV -sC -oA nmap/Bizness 10.10.11.252
Starting Nmap 7.93 ( https://nmap.org ) at 2024-01-13 21:54 IST
Nmap scan report
http://packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.htmlhttps://issues.apache.org/jira/browse/OFBIZ-12812https://lists.apache.org/thread/jmbqk2lp4t4483whzndp5xqlq4f3otg3https://ofbiz.apache.org/download.htmlhttps://ofbiz.apache.org/release-notes-18.12.10.htmlhttps://ofbiz.apache.org/security.htmlhttp://packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.htmlhttps://issues.apache.org/jira/browse/OFBIZ-12812https://lists.apache.org/thread/jmbqk2lp4t4483whzndp5xqlq4f3otg3https://ofbiz.apache.org/download.htmlhttps://ofbiz.apache.org/release-notes-18.12.10.htmlhttps://ofbiz.apache.org/security.htmlhttps://www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467
2023-12-05
Published
Exploited in the wild