Skip to main content

CVE-2013-1768

Severity

7.3

Description

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

Mitigation

We recommend upgrading to a version of this component that is not vulnerable to this specific issue.

Project

Apache TomEE

Category
n/a
Tags
data
functional
Date Disclosed

2013-07-11

Date Discovered

2013-02-19

Apache TomEE 1.5.x

First release:
2012-09-28
CVEs:
119
Support Lifecycle:
Namespace:
javax

Apache TomEE 1.0.x

First release:
2012-04-27
CVEs:
130
Support Lifecycle:
Namespace:
javax
Feel Vulnerable? 

Contact us so we can help you.

* These fields are required.