[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-1768Date: (C)2013-08-22   (M)2023-12-22


The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0099.html
BID-60534
PM86780
PM86786
PM86788
PM86791
RHSA-2013:1862
http://svn.apache.org/viewvc?view=revision&revision=1462076
http://svn.apache.org/viewvc?view=revision&revision=1462225
http://svn.apache.org/viewvc?view=revision&revision=1462268
http://svn.apache.org/viewvc?view=revision&revision=1462318
http://svn.apache.org/viewvc?view=revision&revision=1462328
http://svn.apache.org/viewvc?view=revision&revision=1462488
http://svn.apache.org/viewvc?view=revision&revision=1462512
http://svn.apache.org/viewvc?view=revision&revision=1462558
http://www-01.ibm.com/support/docview.wss?uid=swg21635999
http://www-01.ibm.com/support/docview.wss?uid=swg21644047
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
openjpa-cve20131768-command-execution(82268)

CPE    15
cpe:/a:apache:openjpa:2.0.0
cpe:/a:apache:openjpa:2.2.1
cpe:/a:apache:openjpa:2.2.0
cpe:/a:apache:openjpa:2.1.0
...
CWE    1
CWE-264
OVAL    4
oval:org.secpod.oval:def:45317
oval:org.secpod.oval:def:105849
oval:org.secpod.oval:def:105519
oval:org.secpod.oval:def:105499
...

© SecPod Technologies