7.5
CVSSv2

CVE-2013-1768

Published: 11/07/2013 Updated: 20/04/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The BrokerFactory functionality in Apache OpenJPA 1.x prior to 1.2.3 and 2.x prior to 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote malicious users to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

Vulnerable Product Search on Vulmon Subscribe to Product

apache openjpa 1.0.2

apache openjpa 1.0.3

apache openjpa 2.0.1

apache openjpa 2.1.0

apache openjpa 1.0.0

apache openjpa 1.0.1

apache openjpa 1.2.2

apache openjpa 2.0.0

apache openjpa 1.2.0

apache openjpa 1.2.1

apache openjpa 1.0.4

apache openjpa 1.1.0

apache openjpa 2.1.1

apache openjpa 2.2.0

apache openjpa 2.2.1

Vendor Advisories

Debian Bug report logs - #716937 openjpa: CVE-2013-1768 Package: openjpa; Maintainer for openjpa is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 15 Jul 2013 05:42:02 UTC Severity: grave Tags: confirmed, security Fixed in version o ...