---
cve: "CVE-2023-51467"
severity: "LOW"
cvss: 3.1
epss: "96%"
vendor: "Apache Software Foundation"
kev: false
exploited: false
published: "2023-12-26 15:15:08"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T03:21:20+02:00"
---

# CVE-2023-51467

> 3.1 LOW

## Beschreibung

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

## Referenzen

- <https://ofbiz.apache.org/download.html>
- <https://ofbiz.apache.org/security.html>
- <https://ofbiz.apache.org/release-notes-18.12.11.html>
- <https://issues.apache.org/jira/browse/OFBIZ-12873>
- <https://lists.apache.org/thread/9tmf9qyyhgh6m052rhz7lg9vxn390bdv>
- <https://lists.apache.org/thread/oj2s6objhdq72t6g29omqpcbd1wlp48o>
- <https://www.openwall.com/lists/oss-security/2023/12/26/3>
- <https://www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-51467) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
