SB2013032801 - Remote code execution in Apache OpenJPA
Published: March 28, 2018
Security Bulletin ID
SB2013032801
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Deserialization of untrusted data (CVE-ID: CVE-2013-1768)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The weakness exists due to in the BrokerFactory functionality due to creating local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects. A remote attacker can create a serialized object, leverage improperly secured server programs and execute arbitrary code.
Successful exploitation of the vulnerability my result in system compromise.
Remediation
Install update from vendor's website.