CVE-2013-1768 REJECTED

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

EPSS 14.60% · 94.4th percentile

Risk Scores

EPSS Score
14.60%
94.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSopenjpa0
Ubuntu:14.04:LTSopenjpa0, 2.0.1-1

Timeline

References

Open in Interactive Console →