Description
The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j65f-mvgw-prp2 | Deserialization of Untrusted Data in Apache OpenJPA |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:13:32.789Z
Reserved: 2013-02-19T00:00:00.000Z
Link: CVE-2013-1768
No data.
Status : Deferred
Published: 2013-07-11T22:55:00.833
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-1768
OpenCVE Enrichment
No data.
Github GHSA