CVE-2013-1768

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
References
Link Resource
http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0099.html
http://rhn.redhat.com/errata/RHSA-2013-1862.html
http://svn.apache.org/viewvc?view=revision&revision=1462076
http://svn.apache.org/viewvc?view=revision&revision=1462225
http://svn.apache.org/viewvc?view=revision&revision=1462268
http://svn.apache.org/viewvc?view=revision&revision=1462318
http://svn.apache.org/viewvc?view=revision&revision=1462328
http://svn.apache.org/viewvc?view=revision&revision=1462488
http://svn.apache.org/viewvc?view=revision&revision=1462512
http://svn.apache.org/viewvc?view=revision&revision=1462558
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86780
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86786
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86788
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86791
http://www-01.ibm.com/support/docview.wss?uid=swg21635999
http://www-01.ibm.com/support/docview.wss?uid=swg21644047
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
http://www.securityfocus.com/bid/60534
https://exchange.xforce.ibmcloud.com/vulnerabilities/82268
http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0099.html
http://rhn.redhat.com/errata/RHSA-2013-1862.html
http://svn.apache.org/viewvc?view=revision&revision=1462076
http://svn.apache.org/viewvc?view=revision&revision=1462225
http://svn.apache.org/viewvc?view=revision&revision=1462268
http://svn.apache.org/viewvc?view=revision&revision=1462318
http://svn.apache.org/viewvc?view=revision&revision=1462328
http://svn.apache.org/viewvc?view=revision&revision=1462488
http://svn.apache.org/viewvc?view=revision&revision=1462512
http://svn.apache.org/viewvc?view=revision&revision=1462558
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86780
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86786
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86788
http://www-01.ibm.com/support/docview.wss?uid=swg1PM86791
http://www-01.ibm.com/support/docview.wss?uid=swg21635999
http://www-01.ibm.com/support/docview.wss?uid=swg21644047
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
http://www.securityfocus.com/bid/60534
https://exchange.xforce.ibmcloud.com/vulnerabilities/82268
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:openjpa:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.2.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:50

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0099.html - () http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0099.html -
References () http://rhn.redhat.com/errata/RHSA-2013-1862.html - () http://rhn.redhat.com/errata/RHSA-2013-1862.html -
References () http://svn.apache.org/viewvc?view=revision&revision=1462076 - () http://svn.apache.org/viewvc?view=revision&revision=1462076 -
References () http://svn.apache.org/viewvc?view=revision&revision=1462225 - () http://svn.apache.org/viewvc?view=revision&revision=1462225 -
References () http://svn.apache.org/viewvc?view=revision&revision=1462268 - () http://svn.apache.org/viewvc?view=revision&revision=1462268 -
References () http://svn.apache.org/viewvc?view=revision&revision=1462318 - () http://svn.apache.org/viewvc?view=revision&revision=1462318 -
References () http://svn.apache.org/viewvc?view=revision&revision=1462328 - () http://svn.apache.org/viewvc?view=revision&revision=1462328 -
References () http://svn.apache.org/viewvc?view=revision&revision=1462488 - () http://svn.apache.org/viewvc?view=revision&revision=1462488 -
References () http://svn.apache.org/viewvc?view=revision&revision=1462512 - () http://svn.apache.org/viewvc?view=revision&revision=1462512 -
References () http://svn.apache.org/viewvc?view=revision&revision=1462558 - () http://svn.apache.org/viewvc?view=revision&revision=1462558 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86780 - () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86780 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86786 - () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86786 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86788 - () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86788 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86791 - () http://www-01.ibm.com/support/docview.wss?uid=swg1PM86791 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg21635999 - () http://www-01.ibm.com/support/docview.wss?uid=swg21635999 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg21644047 - () http://www-01.ibm.com/support/docview.wss?uid=swg21644047 -
References () http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html - () http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html -
References () http://www.securityfocus.com/bid/60534 - () http://www.securityfocus.com/bid/60534 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/82268 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/82268 -

Information

Published : 2013-07-11 22:55

Updated : 2024-11-21 01:50


NVD link : CVE-2013-1768

Mitre link : CVE-2013-1768

CVE.ORG link : CVE-2013-1768


JSON object : View

Products Affected

apache

  • openjpa
CWE
CWE-264

Permissions, Privileges, and Access Controls