CVE-2013-1768
Summary
| CVE | CVE-2013-1768 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-11 22:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Openjpa | 1.0.0 | All | All | All |
| Application | Apache | Openjpa | 1.0.1 | All | All | All |
| Application | Apache | Openjpa | 1.0.2 | All | All | All |
| Application | Apache | Openjpa | 1.0.3 | All | All | All |
| Application | Apache | Openjpa | 1.0.4 | All | All | All |
| Application | Apache | Openjpa | 1.1.0 | All | All | All |
| Application | Apache | Openjpa | 1.2.0 | All | All | All |
| Application | Apache | Openjpa | 1.2.1 | All | All | All |
| Application | Apache | Openjpa | 1.2.2 | All | All | All |
| Application | Apache | Openjpa | 2.0.0 | All | All | All |
| Application | Apache | Openjpa | 2.0.1 | All | All | All |
| Application | Apache | Openjpa | 2.1.0 | All | All | All |
| Application | Apache | Openjpa | 2.1.1 | All | All | All |
| Application | Apache | Openjpa | 2.2.0 | All | All | All |
| Application | Apache | Openjpa | 2.2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Apache-SVN] Revision 1462558 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| [Apache-SVN] Revision 1462328 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| archives.neohapsis.com/archives/fulldisclosure/2013-06/0099.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [Apache-SVN] Revision 1462268 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| IBM Security Bulletin: Potential Security Vulnerabilities fixed in IBM WebSphere Application Server 8.0.0.7 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| [Apache-SVN] Revision 1462488 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Oracle Critical Patch Update - April 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Security Bulletin: Potential security vulnerability in WebSphere Application Server CVE-2013-1768 PM86780 | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| [Apache-SVN] Revision 1462318 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| [Apache-SVN] Revision 1462225 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| [Apache-SVN] Revision 1462512 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| [Apache-SVN] Revision 1462076 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.