CVE-2013-1768

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:openjpa:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:openjpa:2.2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-07-11 22:55

Updated : 2024-02-28 12:00


NVD link : CVE-2013-1768

Mitre link : CVE-2013-1768

CVE.ORG link : CVE-2013-1768


JSON object : View

Products Affected

apache

  • openjpa
CWE
CWE-264

Permissions, Privileges, and Access Controls