Back

HIGH

openjpa: Remote arbitrary code execution by creating a serialized object and leveraging improperly secured server programs

Published Jul 11, 2013

Description

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 11, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jun 12, 2013
GHSA-J65F-MVGW-PRP2