PT-2013-3380 · Apache · Apache Openjpa

Publicado

2013-07-11

·

Atualizado

2022-05-14

·

CVE-2013-1768

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache OpenJPA versions 1.x through 1.2.2 Apache OpenJPA versions 2.x through 2.2.1
Description The issue allows remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs. This is made possible because the BrokerFactory functionality in Apache OpenJPA creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects.
Recommendations For Apache OpenJPA versions 1.x through 1.2.2, update to version 1.2.3 or later. For Apache OpenJPA versions 2.x through 2.2.1, update to version 2.2.2 or later.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1768
GHSA-J65F-MVGW-PRP2
MGASA-2013-0292

Produtos afetados

Apache Openjpa