Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
BID:60534
Info
Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
| Bugtraq ID: | 60534 |
| Class: | Unknown |
| CVE: |
CVE-2013-1768 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2013 12:00AM |
| Updated: | Apr 18 2018 06:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat JBoss Fuse 6.0 Redhat Fuse MQ Enterprise 7.1.0 Redhat Fuse ESB Enterprise 7.1.0 Oracle Weblogic Server 12.2.1.3 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Apache OpenJPA 2.2.1 Apache OpenJPA 2.2 Apache OpenJPA 2.1.1 Apache OpenJPA 2.1 Apache OpenJPA 2.0.1 Apache OpenJPA 2.0 Apache OpenJPA 1.3 Apache OpenJPA 1.2.2 Apache OpenJPA 1.2 Apache OpenJPA 1.1 Apache OpenJPA 1.0.4 Apache OpenJPA 1.0 |
| Not Vulnerable: |
Apache OpenJPA 2.2.2 Apache OpenJPA 1.2.3 |
Discussion
Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
Apache OpenJPA is prone to a vulnerability that allows attackers to write or overwrite arbitrary files on a vulnerable computer.
An attacker can exploit this issue to create or overwrite arbitrary files on the computer running the affected application. This may aid in further attacks.
The following products are affected:
OpenJPA 1.0.0 through 1.0.4
OpenJPA 1.1.0
OpenJPA 1.3.0
OpenJPA 1.2.0 through 1.2.2
OpenJPA 2.0.0 through 2.0.1
OpenJPA 2.1.0 through 2.1.1
OpenJPA 2.2.0 through 2.2.1
Apache OpenJPA is prone to a vulnerability that allows attackers to write or overwrite arbitrary files on a vulnerable computer.
An attacker can exploit this issue to create or overwrite arbitrary files on the computer running the affected application. This may aid in further attacks.
The following products are affected:
OpenJPA 1.0.0 through 1.0.4
OpenJPA 1.1.0
OpenJPA 1.3.0
OpenJPA 1.2.0 through 1.2.2
OpenJPA 2.0.0 through 2.0.1
OpenJPA 2.1.0 through 2.1.1
OpenJPA 2.2.0 through 2.2.1
Exploit / POC
Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
-
Mandriva openjpa-2.2.0-3.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva openjpa-javadoc-2.2.0-3.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva openjpa-tools-2.2.0-3.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/
References
Apache OpenJPA Object Deserialization Arbitrary File Creation or Overwrite Vulnerability
References:
References:
- Apache OpenJPA Project Homepage (Apache)
- OpenJPA 1.0.x revision 1462558 (Apache)
- OpenJPA 1.1.x revision 1462512 (Apache)
- OpenJPA 1.2.x revision 1462488 (Apache)
- OpenJPA 1.3.x revision 1462328 (Apache)
- OpenJPA 2.0.x revision 1462318 (Apache)
- OpenJPA 2.1.x revision 1462268 (Apache)
- OpenJPA 2.2.1.x revision 1462225 (Apache)
- OpenJPA 2.2.x revision 1462076 (Apache)
- Important: Fuse ESB Enterprise/Fuse MQ Enterprise 7.1.0 update (Red Hat)
- Oracle Critical Patch Update Advisory - April 2018 (Oracle)